Kernel networking bug in Linux bridge is widely deployed across servers, appliances, and cloud hosts and can enable host compromise; impacts broad IT infrastructure.
CVE-2026-74480
Linux kernel bridge use-after-free enabling kernel RCE via multicast fast-leave
Is CVE-2026-74480 being exploited?
Not confirmed. CVE-2026-74480 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.56% probability of exploitation in the next 30 days.
How severe is CVE-2026-74480?
CVE-2026-74480 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74480?
Yes. A fix has been recorded for CVE-2026-74480. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74480 affect?
CVE-2026-74480 affects Linux kernel (net/bridge), Major Linux distributions (Ubuntu, RHEL, Debian, SUSE), Network appliances using Linux kernel. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74480?
Install vendor/kernel updates immediately; isolate or block untrusted multicast/L2 traffic until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Use-after-free in bridge fast-leave can cause kernel panic or be exploited for kernel-level code execution and full host compromise via crafted multicast traffic.
Immediate action required
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < d6c32e2e25a9a06ba021030e26b6d602a277eb72
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 482bcb85139addb4e8ac8ed10baeda3e0aad4031
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 1a109cc9890d017c41d77e6c82da739579c49f0b
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 159ad90cb929c033308bb39a2c5f8fbf393b77aa
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 4695430e8132420bf8de94da3eb36a6cf35fde6b
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 0309ebbc570000ea0df11c06b69798e5860c5f6f
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < 4c57056ca6aace2e9f94ae9298bf49ef6b0c95e4
- affected>= 6db6f0eae6052b70885562e1733896647ec1d807 and < a39789f211b8a4125f0c70e05b30cf715f4f187d
- affected4.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.