CVE-2026-74583
CVE-2026-74583: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.8
High [CVE-2026-74583] fix fastmap use-after-free on filter
CVE-2026-74583Source published Source updated
In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifier maintains a 16-slot fastmap cache that stores raw struct route4_filter pointers indexed by (id, iif). The reader (route4_classify) populates this cache via route4_set_fastmap() for every classified packet that hits a filter. The writer (route4_delete, route4_change) clears the cache via route4_reset_fastmap() before RCU-deferred kfree of the filter. This creates a UAF race: 1. Reader walks the RCU-protected bucket chain, finds filter f 2. Writer unlinks f, calls route4_reset_fastmap(), then tcf_queue_work() 3. Reader calls route4_set_fastmap() and writes f into the cache *after* the writer's reset, caching a pointer about to be freed 4.…
- Affected products in this advisory
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat package: kernel-rt
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- To mitigate this vulnerability, prevent the `cls_route` kernel module from loading. This can be achieved by creating a modprobe configuration file. 1. Create or edit `/etc/modprobe.d/disable-cls_route.conf` and add the following line: `install cls_route /bin/true` 2. Regenerate the initramfs to ensure the change takes effect on boot: `dracut -f -v` 3. Reboot the system for the changes to be applied. Note that disabling this module may impact network traffic classification functionality if it is actively used.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.