Linux Kernel xsk TX Metadata Length Vulnerability (CVE-2026-74710)
CVE-2026-74710 Published on August 22, 2026
xsk: require at least 16 bytes of TX metadata
In the Linux kernel, the following vulnerability has been resolved:
xsk: require at least 16 bytes of TX metadata
AF_XDP accepts a TX metadata length as small as eight bytes, but every
supported request needs the flags plus at least one eight-byte request
field. Such short metadata also lets the kernel read beyond the registered
area.
Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve
compatibility with applications that do not use launch-time metadata.
Products Associated with CVE-2026-74710
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 341ac980eab90ac1f6c22ee9f9da83ed9604d899 and below 21b8536aee819792f1b4b38b9aacf2a073025d49 is affected.
- Version 341ac980eab90ac1f6c22ee9f9da83ed9604d899 and below 642c6e73fce17fdca93a5793c4d22359fda866d7 is affected.
- Version 341ac980eab90ac1f6c22ee9f9da83ed9604d899 and below cfb9d2976b277e554e28c165e3eff4b4a8ea10bd is affected.
- Version 341ac980eab90ac1f6c22ee9f9da83ed9604d899 and below 1bb30b181d9f0484e141f8411e15ed906d5c6780 is affected.
- Version 6.8 is affected.
- Before 6.8 is unaffected.
- Version 6.12.104, <= 6.12.* is unaffected.
- Version 6.18.45, <= 6.18.* is unaffected.
- Version 7.1.9, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.