CVE-2026-74283 is an improper authorization vulnerability in the Linux kernel TIPC subsystem's TIPCv2 generic-netlink interface. Mutating operations were registered without generic-netlink administrative-permission flags, so they did not enforce the namespace-aware CAP_NET_ADMIN check required for administrative TIPC actions. A local unprivileged process could invoke operations to alter TIPC network configuration, node identity, key material, and bearer state. The fix applies GENL_UNS_ADMIN_PERM to the affected mutating operations, aligning TIPCv2 behavior with the legacy TIPC netlink API and preserving valid administration from non-initial user namespaces.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone Linux-kernel exploit/reproduction repository for CVE-2026-52993, a TIPC fragment-reassembly double-free in net/tipc/msg.c:tipc_buf_append(). Its core network trigger is harness/fakepeer.c, a C userspace fake TIPC peer that uses an ordinary UDP socket rather than the host TIPC stack. It emits forged TIPC discovery traffic, an ACTIVATE control message, and repeated malformed MSG_FRAGMENTER sequences to port 6118. The malformed final fragment causes validation to reallocate and free a reassembled skb while the caller retains a stale pointer, resulting in a second free. The harness directory contains Bash build, initramfs, namespace, local-trigger, and two-QEMU-guest orchestration scripts. It builds KASAN-enabled 6.6.140 and 6.6.141 kernels for vulnerable-versus-fixed controls, and includes a separate pwn build profile with KASAN and slab debugging disabled. README, notes, diagrams, patches, and extensive logs document both KASAN trigger evidence and a specialized heap-exploitation chain. That chain measures the corrupted kmalloc-704 freelist, uses fork allocations and 324-byte AF_UNIX datagrams to overwrite a live files_struct, redirects file-descriptor-table pointers to user-controlled memory, and calls close(63) to reach override_creds using a forged credential. The file listing references pwn helpers such as tipcroot and udprelay through build scripts and documentation, although their poc/ source directory is not present in the supplied 100-file listing. Evidence logs distinguish a raw remote trigger from the more constrained remote LPE demonstration. The former is reported against a victim running TIPC over UDP; the latter uses a root-run victim relay from 10.10.0.2:6118 to loopback so that a specific slab allocation geometry is recreated. Therefore, the unauthenticated remote crash/UAF trigger is materially broader than the documented root-escalation configuration. The repository is not part of Metasploit, Nuclei, or another recognized exploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.