Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()… (CVE-2026-74695)

0
Medium
Published: 08/22/2026 (08/22/2026, 18:30:29 UTC)
Source: GCVE Database

Description

A vulnerability in the Linux kernel's netfilter subsystem related to the nf_flow_table component has been resolved. The issue involves improper handling of existing destination entries (dst_entry) in socket buffers (skbs) when passing through netfilter flowtable offload hooks or XFRM offload paths. Specifically, calling skb_dst_set_noref() without dropping an existing ref-counted dst_entry causes a reference count leak and triggers a kernel warning. The fix involves dropping any existing dst_entry reference before setting the non-referenced flowtable destination.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/23/2026, 00:24:32 UTC

Technical Analysis

The vulnerability in the Linux kernel netfilter nf_flow_table occurs because incoming skbs may already have a ref-counted dst_entry assigned from earlier processing. When skb_dst_set_noref() is called on such skbs without first dropping the existing dst_entry reference, it overwrites skb->_skb_refdst, leaking the previous reference count and causing a DEBUG_NET_WARN_ON_ONCE assertion in skb_dst_check_unset(). The patch addresses this by ensuring skb_dst_drop(skb) is called before setting the non-referenced flowtable destination, preventing the reference count leak and kernel warnings.

Potential Impact

The vulnerability leads to a reference count leak in the kernel's networking stack, which can trigger kernel warnings and potentially destabilize the system or cause unexpected behavior in network packet processing. There is no indication of direct code execution or privilege escalation from this issue based on the provided data.

Mitigation Recommendations

A fix has been applied to the Linux kernel to drop any existing dst_entry reference before calling skb_dst_set_noref(). Users should update their Linux kernel to a version that includes this fix. Since no patch links or specific fixed versions are provided, users should consult their Linux distribution or kernel vendor advisories for the official patched versions. Patch status is not yet confirmed in this data — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-cx4h-xjm7-pqxp
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74695"]
Ecosystems
[]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a8a27f1acd9273b499bc766

Added to database: 08/22/2026, 22:51:29 UTC

Last enriched: 08/23/2026, 00:24:32 UTC

Last updated: 08/23/2026, 01:52:02 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses