Use-after-free in Linux kernel - CVE-2026-74677
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the ipheth carrier_work logic in drivers/net/usb/ipheth.c when handling USB disconnect and TX URB completion events. A local user can trigger link down and unplug conditions while a TX URB is in flight to cause a denial of service.
Exploitation requires an attached USB device that stops draining bulk OUT, and the described reproducer was driven as root.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74677
linux (Debian package) - update to 6.12.105-1