Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-74669

CVE-2026-74669: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.8

    High [CVE-2026-74669] clear IPv4 options after rebasing tunnel ICMP errors

    CVE-2026-74669Source published Source updated

    In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt still describes the outer IPv4 header. A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ip_options_echo() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the __icmp_send() stack, causing a stack out-of-bounds write. Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 7
    • Red Hat Enterprise Linux 8
    • Red Hat Enterprise Linux 9

    1 more entries in the full advisory.

    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • To mitigate this issue, prevent the `ip_vs` kernel module from loading. This can be achieved by creating a blacklist rule. 1. Unload the module if currently loaded: `sudo modprobe -r ip_vs` 2. Create a blacklist configuration file: `echo "blacklist ip_vs" | sudo tee /etc/modprobe.d/disable-ip_vs.conf` 3. Rebuild the initial RAM disk to ensure the module is not loaded at boot: `sudo dracut -f` A system reboot is required for the changes to take full effect. Disabling this module will prevent the use of IP Virtual Server (IPVS) functionality.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery