What is CVE-2026-74474?
This Linux kernel vulnerability in the vxlan module relates to unsafe header pulls using pskb_may_pull() instead of pskb_network_may_pull() in the transmit path. It could potentially lead to denial of service or information leaks due to improper validation. Affected systems should apply the kernel update.
Azərbaycanca: Bu Linux kernel zəifliyi vxlan modulunda şəbəkə başlıqlarının çəkilməsi zamanı pskb_may_pull() əvəzinə daha təhlükəsiz pskb_network_may_pull() funksiyasının istifadə edilməməsi ilə bağlıdır. Potensial olaraq paket ötürülməsi zamanı zəif yoxlama səbəbindən xidmət rəddi (DoS) və ya məlumat sızması yarana bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
FAQ2
Which module of the Linux kernel is affected by CVE-2026-74474?
This vulnerability affects the vxlan module of the Linux kernel.
What security risks can CVE-2026-74474 pose?
It could potentially lead to denial of service or information leaks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.