Incorrect behavior order in Linux kernel - CVE-2026-74691
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper shutdown sequence in the thunderbolt networking teardown logic when disabling thunderbolt DMA paths during interface teardown. A local user can trigger interface teardowns to cause a denial of service.
On affected systems, repeated teardowns can eventually take the XDomain control channel down, after which the peer node disappears until the controller is power cycled.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74691
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0da9a6d27155ad072dd76db8cd637feead99a0e0
- https://git.kernel.org/stable/c/103a9b663ac1cacb8465aeff18f84a247154a562
- https://git.kernel.org/stable/c/4dd71cb0d23d40cb58fe4261c7bd183dca66caa0
- https://git.kernel.org/stable/c/68bf02b6b4ad3f748c6db71fd77b6c0402d252f4
- https://git.kernel.org/stable/c/7cce39109206bc5497e0953806563644b88bfc44
- https://git.kernel.org/stable/c/9a482b2b117e5fa656b6d24fc01799e8ac2d4368
- https://git.kernel.org/stable/c/b5a21615f627c48dafaa6ef82a34a5b97a4352aa