securityonline.info 8/24/2026, 7:51:28 AM · external

CVE-2026-74480: Linux kernel bridge flaw grants local root

CVE-2026-74480: Linux kernel bridge flaw grants local root
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

CVE- 2026-74480 is a critical privilege escalation vulnerability found in the Linux kernel's network bridge module, with a CVSS score of 9.8. Discovered by Nebula Security, this use-after-free bug allows local attackers to escalate privileges to root. Although public exploit code is available, no in-the-wild exploitation has been reported. The flaw affects multiple kernel versions since its introduction in January 2017 but has been patched in July 2026. Users are advised to update to the latest patched versions to mitigate the risk.

View Primary Source Via securityonline.info

Article by CyberSIXT