Improper resource shutdown or release in Linux kernel - CVE-2026-74680
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in cxacru_cm() in the cxacru usb atm driver when handling error conditions during urb submission and command processing. A local user can trigger an error path that leaves rcv_urb active to cause a denial of service.
The issue can be reached during device initialization when a subsequent status poll invokes the same command path again, leading to a warning when the active urb is resubmitted.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74680
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0af047703dbed8224552587ed436f14a24371b46
- https://git.kernel.org/stable/c/2f73a065791d2a8e3f0bdf29248e33600359e865
- https://git.kernel.org/stable/c/61093d7f1144f6a15bac505df35e5f535ade2ac1
- https://git.kernel.org/stable/c/6133b461058316e3ccba7331f974d110d4c08b23
- https://git.kernel.org/stable/c/645d98dbccdbfdbf0129f48822af7183492de091
- https://git.kernel.org/stable/c/939b6a41f681aea52af678053072ee443068e93e
- https://git.kernel.org/stable/c/993f7677949e3d72e360e86eed1f41c2511f75ed
- https://git.kernel.org/stable/c/c2f811314be351d86b6ab41e9297ae80d8da6f86