Uncontrolled Recursion in Linux kernel - CVE-2026-74576
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the slab free path in mm/slub.c when freeing slab object extension arrays involved in cyclic kmalloc cache relationships. A local user can trigger memory allocation and freeing patterns to cause a denial of service.
Exploitation requires memory allocation profiling or slab object extension handling to be active, and the issue can exhaust the kernel stack.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74576
linux (Debian package) - update to 6.12.105-1