SB2026082481 - Incorrect behavior order in Linux kernel net thunderbolt driver



SB2026082481 - Incorrect behavior order in Linux kernel net thunderbolt driver

Published: August 24, 2026

Security Bulletin ID SB2026082481
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Incorrect behavior order (CVE-ID: CVE-2026-74691)

CWE-ID: CWE-696 - Incorrect Behavior Order

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper shutdown sequence in the thunderbolt networking teardown logic when disabling thunderbolt DMA paths during interface teardown. A local user can trigger interface teardowns to cause a denial of service.

On affected systems, repeated teardowns can eventually take the XDomain control channel down, after which the peer node disappears until the controller is power cycled.


Remediation

Install update from vendor's website.