In the Linux kernel, the following vulnerability has been resolved:
forcedeth: fix UAF of txrx_stats in nv_remove
nv_remove() frees the per-CPU txrx_stats before unregister_netdev().
Until unregister completes, ndo_get_stats64, the NAPI/xmit data path,
and nv_close()/drain may still access txrx_stats, leading to a
use-after-free.
Free the stats only after unregister_netdev().
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-15 13:18
Updated : 2026-08-19 17:21
NVD link : CVE-2026-74548
Mitre link : CVE-2026-74548
CVE.ORG link : CVE-2026-74548
JSON object : View
Products Affected
No product.
CWE
No CWE.
