{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.8-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nexthop: take nh-\u003elock for f6i_list walks in replace check and notify  fib6_check_nh_list() and __nexthop_replace_notify() walk nh-\u003ef6i_list during an RTNL-serialized nexthop replace without holding nh-\u003elock. IPv6 RTM_NEWROUTE/RTM_DELROUTE run without RTNL and mutate that list under nh-\u003elock (fib6_add_rt2node_nh(), fib6_purge_rt()), so both walks race a concurrent route delete that unlinks and frees a fib6_info:    BUG: KASAN: slab-use-after-free in rt6_fill_node.isra.0 (net/ipv6/route.c:5799)   Read of size 4 at addr ffff888014607e64 by task exploit/143    rt6_fill_node.isra.0 (net/ipv6/route.c:5799)    fib6_rt_update (net/ipv6/route.c:6412)    __nexthop_replace_notify (net/ipv4/nexthop.c:2542)    rtm_new_nexthop (net/ipv4/nexthop.c:2554)    rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)    BUG: KASAN: slab-use-after-free in fib6_check_nh_list (net/ipv4/nexthop.c:1605)   Read of size 8 at addr ffff888014a7d068 by task exploit/142    fib6_check_nh_list (net/ipv4/nexthop.c:1605)    rtm_new_nexthop (net/ipv4/nexthop.c:2575)    rtnetlink_rcv_msg (net/core/rtnetlink.c:7076)  Both walks only read the entries and take no tb6_lock, so protect them with nh-\u003elock; fib6_rt_update() uses gfp_any(), which returns GFP_ATOMIC under the lock.",
  "id": "DEBIAN-CVE-2026-74562",
  "modified": "2026-09-14T16:47:31.975663348Z",
  "published": "2026-08-15T13:18:01.690Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-74562"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-74562"
  ]
}