Race condition in Linux kernel - CVE-2026-74662
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a race condition in inet_frag_create() and the fragment queue timer handling in net/ipv4/inet_fragment.c when processing fragmented packets with a zero or negative fragment timeout. A remote attacker can send specially crafted fragmented network traffic to cause a denial of service.
The issue occurs because the timer may run before the queue is published in the fqdir rhashtable, which can leave a stale hash node after reference handling becomes unbalanced.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74662
linux (Debian package) - update to 6.12.107-1