SB20260824197 - Improper resource shutdown or release in Linux kernel aquantia atlantic driver



SB20260824197 - Improper resource shutdown or release in Linux kernel aquantia atlantic driver

Published: August 24, 2026

Security Bulletin ID SB20260824197
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper resource shutdown or release (CVE-ID: CVE-2026-74623)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown in the atlantic driver TX ring deinitialization logic when tearing down network interfaces under TX or XDP_TX load. A local user can trigger interface teardown while transmit descriptors remain stranded to cause a denial of service.

Under XDP_TX load, stranded frames can keep the page pool inflight count above zero and prevent pool shutdown, with repeated stall warnings during interface down, XDP detach, or ring resize operations.


Remediation

Install update from vendor's website.