Incorrect behavior order in Linux kernel - CVE-2026-74691

 

Incorrect behavior order in Linux kernel - CVE-2026-74691

Published: August 24, 2026


Vulnerability identifier: #VU144663
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74691
CWE-ID: CWE-696
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper shutdown sequence in the thunderbolt networking teardown logic when disabling thunderbolt DMA paths during interface teardown. A local user can trigger interface teardowns to cause a denial of service.

On affected systems, repeated teardowns can eventually take the XDomain control channel down, after which the peer node disappears until the controller is power cycled.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74691

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins