Memory leak in Linux kernel - CVE-2026-74494
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a memory leak in smb2_handle_negotiate() and connection negotiation state handling when sending repeated SMB2 NEGOTIATE requests on one connection before SESSION_SETUP. A remote attacker can send multiple successful SMB2 NEGOTIATE requests to cause a denial of service.
The issue occurs after a dialect has already been selected and before session setup completes.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74494
linux (Debian package) - update to 6.12.105-1