Improper resource shutdown or release in Linux kernel - CVE-2026-74550
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource shutdown in ICMP/NDISC redirect handling when peer allocation fails under memory pressure or peer tree size caps. A remote attacker can trigger packet forwarding conditions that cause un-rate-limited ICMP/NDISC Redirect messages to be sent to cause a denial of service.
The issue affects both IPv4 and IPv6 redirect paths.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74550
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/21666f7af49a90ef44d474916b8ef4402dfd74f5
- https://git.kernel.org/stable/c/5ec5f00fc606a6df8434948c4552b3cb1176595d
- https://git.kernel.org/stable/c/828f6670d110ff2bf44c743037b38badc315704c
- https://git.kernel.org/stable/c/dbc3791e3b2472e1ccc08947e0f83b443470ff4f
- https://git.kernel.org/stable/c/f5ecaa7ea7686fa7ecdb6affc9d3a9a42e4524b1