The Linux kernel assigned CVE-2026-74684 to a denial-of-service flaw in the TAP networking path that can allow a malicious guest VM using virtio-net to panic its host. The condition affects configurations using vhost-net with a TAP-backed interface, including macvtap; crafted malformed packets can reach the vulnerable processing path and crash the host kernel. A mainline fix was merged in commit 3874892dd27d5387aa9a06f58d9060f18f351d24.
The defect is related to CVE-2022-50073: its earlier remediation covered tap_get_user() but omitted tap_get_user_xdp(). The issue follows prior scrutiny of ownership handling in Linux TUN/TAP drivers, including a 2023 patch series proposing sk_uid initialization from current_fsuid() for issues associated with CVE-2023-1076; however, the newly assigned CVE concerns the missed XDP packet-ingestion path and guest-to-host crash risk.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Laszlo Ersek publicly submitted a two-patch series to re-fix CVE-2023-1076 in the Linux TUN/TAP drivers after determining the prior fixes were incorrect. The patches set sk_uid from current_fsuid() in tun_chr_open() and tap_open(), and Ersek reported reproducing the issue in both TUN and TAP.
A Linux kernel TAP networking flaw that can let a virtio-net guest send malformed packets and panic a vulnerable vhost-net host was assigned CVE-2026-74684. The affected configuration includes a TAP backend such as macvtap, although other TAP device users may also be affected.
A fix titled "net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp()" was merged into the mainline Linux kernel as commit 3874892dd27d5387aa9a06f58d9060f18f351d24. The change addresses an uncovered path left by the earlier CVE-2022-50073 fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.