Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74709

Published Aug 22, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-74709 is a known-severity vulnerability. It was published on August 22, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

xsk: clear metadata pointer when no timestamp is requested

User space can change metadata flags after request processing. Rereading

them during completion can therefore make the kernel write a timestamp

that was not requested when the packet was submitted.

Clear the metadata pointer during request processing unless timestamp

completion is requested. Completion handling can then use the pointer

itself instead of rereading the flags.

On the mlx5 multi-packet WQE path metadata is evaluated per batch:

xsk_tx_metadata_request() runs only for the descriptor that starts a

session, just like the checksum offload that is applied once through the

shared WQE. Only that descriptor's pointer is reset, so completion

handling can record a timestamp for the other descriptors of the session

regardless of their own XDP_TXMD_FLAGS_TIMESTAMP bit. The write stays

inside the metadata area; the single-WQE, other zero-copy, and generic

pa

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74709?

CVE-2026-74709 is a known-severity vulnerability. It was published on August 22, 2026.

How severe is CVE-2026-74709?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74709?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74709?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74709 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.