Improper resource shutdown or release in Linux kernel - CVE-2026-74626
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in ntb_netdev_rx_handler() in the ntb_netdev driver when handling received packets and allocating replacement receive buffers. A remote attacker can send packets that trigger allocation failures and exhaust the receive queue to cause a denial of service.
The issue can stall packet reception while the network interface remains up.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74626
linux (Debian package) - update to 6.12.107-1