CVE-2026-74714 | Linux Kernel up to 7.1.8 BPF TCP Iterator lib/refcount.c bpf_iter_tcp_established_batch rsk_refcnt use after free

SecurityVulns

A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.1.182/6.6.151/6.12.103/6.18.44/7.1.8. This vulnerability affects the function bpf_iter_tcp_established_batch of the file lib/refcount.c of the component BPF TCP Iterator. This manipulation of the argument rsk_refcnt causes use after free.

This vulnerability is tracked as CVE-2026-74714. The attack is restricted to local execution. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More