Memory leak in Linux kernel - CVE-2026-74625

 

Memory leak in Linux kernel - CVE-2026-74625

Published: August 24, 2026


Vulnerability identifier: #VU144935
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74625
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in nf_ct_bridge_pre() when processing non-IPv4 and non-IPv6 Ethernet frames after a bridge nftables ct zone set rule has attached a conntrack template. A remote attacker can send specially crafted non-IP traffic to cause a denial of service.

Memory is leaked by making the existing conntrack template reference unreachable, which can exhaust slab memory.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74625

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins