CVE-2026-74544: net/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
In the Linux kernel, the following vulnerability has been resolved:
net/sched: clsu32: validate offshift to prevent shift-out-of-bounds
u32change() copies the user-provided tcu32sel.offshift (unsigned char, 0-255) into the kernel knode object without bounds validation. When a packet later hits u32classify() with TCU32VAROFFSET set, it evaluates ntohs(offmask & data) >> offshift where the left operand is a 16-bit value promoted to a 32-bit int. Any offshift >= 32 is undefined behavior per C11 6.5.7p3, triggerable by an unprivileged user via user/network namespaces.
UBSAN: shift-out-of-bounds in net/sched/clsu32.c:236:43 shift exponent 32 is too large for 32-bit type int
Fix this by rejecting offshift >= 16 during filter creation in u32change().
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
During u32 filter creation, reject any tc_u32_sel.offshift value where offshift is >= 16 to prevent shift-out-of-bounds in cls_u32.c (UBSAN: shift-out-of-bounds in net/sched/cls_u32.c:236:43).
Linux kernel (net/sched/cls_u32.c / cls_u32 filter creation) tc_u32_sel.offshift validation = Reject offshift >= 16
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74544?
CVE-2026-74544 has a risk level of 37, indicating a significant vulnerability in the Linux kernel.
How do I fix CVE-2026-74544?
To fix CVE-2026-74544, update your Linux kernel to the latest version that includes the necessary patch.
What does CVE-2026-74544 affect?
CVE-2026-74544 affects the Linux kernel's network scheduling component, specifically the cls_u32 class.
What type of vulnerability is CVE-2026-74544?
CVE-2026-74544 is an input validation vulnerability that can lead to shift-out-of-bounds issues.
When was CVE-2026-74544 published?
CVE-2026-74544 was published on August 15, 2026.