Improper resource shutdown or release in Linux kernel - CVE-2026-74678

 

Improper resource shutdown or release in Linux kernel - CVE-2026-74678

Published: August 24, 2026


Vulnerability identifier: #VU144735
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74678
CWE-ID: CWE-404
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource shutdown or release in ax88179_tx_fixup() when processing transmitted socket buffers with NETIF_F_SG enabled and skb_linearize() fails. A local user can trigger transmission of packets under memory pressure to cause a denial of service.

The issue occurs because the socket buffer is not freed when the function returns NULL on the linearization failure path.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74678

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins