CVE-2026-74670
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ipvs: stop estimator after disabled calc phase<br />
<br />
IPVS estimator kthread 0 starts with zeroed chain and tick limits until<br />
its initial calculation phase completes. If network namespace teardown<br />
clears ipvs->enable during that phase, ip_vs_est_calc_phase() can return<br />
without installing positive limits.<br />
<br />
The kthread can then continue into its main loop and drain<br />
est_temp_list with zero chain_max, tick_max and est_max_count values.<br />
Each enqueue consumes one available tick row, but est_count never<br />
reaches the zero est_max_count value. After all rows are consumed, the<br />
row lookup returns IPVS_EST_NTICKS and ip_vs_enqueue_estimator() writes<br />
past the ticks and tick_len arrays.<br />
<br />
Exit kthread 0 after the calculation phase if the kthread is stopping or<br />
IPVS has been disabled. That keeps temporary estimators from being<br />
drained after the limits failed to initialize.<br />
<br />
Estimator kthreads can now self-exit before teardown or reload stops<br />
kd->task. Keep an extra task reference after creation and release it<br />
with kthread_stop_put(), so kd->task remains valid until the stop paths<br />
consume that reference.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/2335dedc1922dfa889ca1f9f70370924e8e79a08
- https://git.kernel.org/stable/c/558f67f1340f803a346ecd14a69c49653111c5f4
- https://git.kernel.org/stable/c/d5122a2b2601145975d387006e517c56896e310e
- https://git.kernel.org/stable/c/de98dc5ef94b83bbb444c670c253ea02ca0f5e43
- https://git.kernel.org/stable/c/e7f34f29b330265d456943bf0b984dcecfcef9af


