Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74696
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper state management in TCP Fast Open listener queue accounting when migrating pending Fast Open children across SO_REUSEPORT listeners. A remote attacker can establish multiple pending Fast Open requests during listener migration to cause a denial of service.
This only occurs with SO_REUSEPORT listener migration involving still-pending TCP Fast Open children.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74696
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/585fc5247d14939a561056aa2addd9b7c2b1f670
- https://git.kernel.org/stable/c/6e10ee56524a26b250229ad348637825646ddb88
- https://git.kernel.org/stable/c/a0ab2ba83e35159d81cec830a92e885ecf8139be
- https://git.kernel.org/stable/c/a66e869cf0c90c1e47ae75f72b6482acbfc808ff
- https://git.kernel.org/stable/c/b6247e0f96bd825ffb2005257f6177b5e642dee6
- https://git.kernel.org/stable/c/d974618b2097453778389d385e3741629c40e0a3
- https://git.kernel.org/stable/c/e98f0d80b9cccb5f828425d2004f9686e7d1ae24