Improper resource shutdown or release in Linux kernel - CVE-2026-74678
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in ax88179_tx_fixup() when processing transmitted socket buffers with NETIF_F_SG enabled and skb_linearize() fails. A local user can trigger transmission of packets under memory pressure to cause a denial of service.
The issue occurs because the socket buffer is not freed when the function returns NULL on the linearization failure path.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74678
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1c63303659a2264bd55d9813df74cb4caeed5922
- https://git.kernel.org/stable/c/1f428e30947395d9b9aacee03e25a4e6cfcad7a4
- https://git.kernel.org/stable/c/2be5091fa693b9119ad25a8bb8c149d236a23ade
- https://git.kernel.org/stable/c/4039cd807a5a46dc5f7618fffae926b8ad8455eb
- https://git.kernel.org/stable/c/58733b1dd46bb231d9d279c132a20ee46da1b664
- https://git.kernel.org/stable/c/83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b