Deadlock in Linux kernel - CVE-2026-74523
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local attacker to cause a denial of service.
The vulnerability exists due to a deadlock in the qede recovery path when handling a TX timeout on a qede NIC with VXLAN/GENEVE tunnel ports configured. A local attacker can trigger a TX timeout condition to cause a denial of service.
The issue can wedge the rtnetlink control plane of the whole machine while the node may still answer ping.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74523
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/451c9075d6c53f2438d110addbeeeea6fac18567
- https://git.kernel.org/stable/c/4626df3f63c9185efba5750fe76ac01ab3351bae
- https://git.kernel.org/stable/c/6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27
- https://git.kernel.org/stable/c/e382a4efeeae6555b95d9ff336cf3094ee7d336b
- https://git.kernel.org/stable/c/e51becb8f3377a377171ed5bf0082b96e22e6292