CVE-2026-74736

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
27/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net/sched: cls_bpf: reject dev-bound programs bound to a different device<br /> <br /> cls_bpf_prog_from_efd() obtained a SCHED_CLS program via<br /> bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)<br /> program&amp;#39;s bound netdev matches the TC netdev the classifier is being<br /> attached to. This let a program loaded with prog_ifindex for device A be<br /> attached via cls_bpf + skip_sw to device B; deleting device A then<br /> destroyed the program&amp;#39;s offload state while it was still attached to<br /> device B, triggering a netdevsim WARN (panic with panic_on_warn=1).<br /> <br /> Mirror the XDP attach path (net/core/dev.c) and reject the attach with<br /> -EINVAL when a dev-bound program&amp;#39;s bound device does not match the<br /> target device.