SB2026082481 - Incorrect behavior order in Linux kernel net thunderbolt driver
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect behavior order (CVE-ID: CVE-2026-74691)
CWE-ID: CWE-696 - Incorrect Behavior Order
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown sequence in the thunderbolt networking teardown logic when disabling thunderbolt DMA paths during interface teardown. A local user can trigger interface teardowns to cause a denial of service.
On affected systems, repeated teardowns can eventually take the XDomain control channel down, after which the peer node disappears until the controller is power cycled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0da9a6d27155ad072dd76db8cd637feead99a0e0
- https://git.kernel.org/stable/c/103a9b663ac1cacb8465aeff18f84a247154a562
- https://git.kernel.org/stable/c/4dd71cb0d23d40cb58fe4261c7bd183dca66caa0
- https://git.kernel.org/stable/c/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4
- https://git.kernel.org/stable/c/7cce39109206bc5497e0953806563644b88bfc44
- https://git.kernel.org/stable/c/9a482b2b117e5fa656b6d24fc01799e8ac2d4368
- https://git.kernel.org/stable/c/b5a21615f627c48dafaa6ef82a34a5b97a4352aa