Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74670

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ipvs: stop estimator after disabled calc phase<br /> <br /> IPVS estimator kthread 0 starts with zeroed chain and tick limits until<br /> its initial calculation phase completes. If network namespace teardown<br /> clears ipvs-&gt;enable during that phase, ip_vs_est_calc_phase() can return<br /> without installing positive limits.<br /> <br /> The kthread can then continue into its main loop and drain<br /> est_temp_list with zero chain_max, tick_max and est_max_count values.<br /> Each enqueue consumes one available tick row, but est_count never<br /> reaches the zero est_max_count value. After all rows are consumed, the<br /> row lookup returns IPVS_EST_NTICKS and ip_vs_enqueue_estimator() writes<br /> past the ticks and tick_len arrays.<br /> <br /> Exit kthread 0 after the calculation phase if the kthread is stopping or<br /> IPVS has been disabled. That keeps temporary estimators from being<br /> drained after the limits failed to initialize.<br /> <br /> Estimator kthreads can now self-exit before teardown or reload stops<br /> kd-&gt;task. Keep an extra task reference after creation and release it<br /> with kthread_stop_put(), so kd-&gt;task remains valid until the stop paths<br /> consume that reference.

Impacto