---
cve: "CVE-2026-74657"
severity: "LOW"
cvss: 3.1
epss: "2.7%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-22 16:16:39"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-07T09:11:32+02:00"
---

# CVE-2026-74657

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

ipv4: Fix fib_nlmsg_size() for RTA_VIA nexthops

fib_nlmsg_size() still estimates nexthop space as if every gateway is
encoded as an IPv4 RTA_GATEWAY attribute. IPv4 routes can also carry an
IPv6 gateway, which fib_nexthop_info() dumps as RTA_VIA.

As a result, route notifications can allocate an skb that is too small.
fib_dump_info() then fails with -EMSGSIZE and rtmsg_fib() hits the
WARN_ON() that marks such failures as a fib_nlmsg_size() bug. With
panic_on_warn set, this becomes a kernel panic.

Mirror the actual nexthop dump layout in fib_nlmsg_size(): account for
IPv6 nexthop gateways dumped as RTA_VIA, for the no-header rtnexthop
layout used inside RTA_MULTIPATH, and for RTA_FLOW only when it is
actually present.

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.267
- Kernel ≥ 5.15.216
- Kernel ≥ 6.1.183
- Kernel ≥ 6.6.152
- Kernel ≥ 6.12.104
- Kernel ≥ 6.18.45
- Kernel ≥ 7.1.9

## Referenzen

- <https://git.kernel.org/stable/c/0f0ca602941d0a81ae9514943ca06c55159c6385>
- <https://git.kernel.org/stable/c/4a5dfbae5179f6574695012a980476254df2d295>
- <https://git.kernel.org/stable/c/4ff9548d84945d2cbf9e4c207288063a200ea397>
- <https://git.kernel.org/stable/c/5307a53599fa762c06e475ee4a375252074fd324>
- <https://git.kernel.org/stable/c/57195f0ab5cfbb5ee0864e5aff15ceb48f5a5e28>
- <https://git.kernel.org/stable/c/7f80ad373ce4a7af5367ff273cea0f16e91387f3>
- <https://git.kernel.org/stable/c/9b22f13524fa0de0d963bbd3002df6c28bae3395>
- <https://git.kernel.org/stable/c/a59edda6eda1252340354322d8ab318b2e9052fb>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-74657) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
