SB20260824215 - Improper resource shutdown or release in Linux kernel sched
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2026-74621)
CWE-ID: CWE-404 - Improper Resource Shutdown or Release
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the act_ct traffic control action when processing malformed fragmented IPv4 or IPv6 packets during header sanity checks. A remote attacker can send a specially crafted malformed packet to cause a denial of service.
The issue can leak one sk_buff and its associated data buffer per malformed packet, which may occur on ingress or egress paths that use the connection tracking action.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/23e97d594ddd0153020c506d5041048fbde1beb4
- https://git.kernel.org/stable/c/439d3e404f9d5e515911cc8132cde198b337c19e
- https://git.kernel.org/stable/c/47d99828591d0fe8be4b9c8992ff3b8e47968db9
- https://git.kernel.org/stable/c/737873a59905a54ca0d2d127ef882f3f88bf4379
- https://git.kernel.org/stable/c/8a7ed561671aa6a911a2de99e59ef670a4d0b1df
- https://git.kernel.org/stable/c/b47bb899e04b5407c5a63fe88d4b6676586a6e84
- https://git.kernel.org/stable/c/b5dbecc2016e1692fd1c2532af9c41ba729cb747