Improper input validation in Linux kernel - CVE-2026-74620
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in act_gact and act_police fallback control action handling when configuring traffic control actions through user-supplied netlink attributes. A local user can supply a crafted fallback control action value to cause a denial of service.
The issue can cause an unbounded sk_buff memory leak for each packet traversing the affected filter chain, including kernel-generated packets.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74620
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/2e8df8c9190335475a3b64a159d3efd8cdd1cb73
- https://git.kernel.org/stable/c/5344e01179baa37547ab29fd7b8614f83faa190c
- https://git.kernel.org/stable/c/5f038affdacaffedf6a85a06cf59ec0a852d36a7
- https://git.kernel.org/stable/c/6bcb8839aa2d686964a4154650afc4db91e1c514
- https://git.kernel.org/stable/c/725efc2ab4a40affc4e285a2dc4896d103948a6c
- https://git.kernel.org/stable/c/883b56ae58fe657d8497806c7059646e9ba6dbd0
- https://git.kernel.org/stable/c/92f00f1d4d204a428b38e26fce3baee144b6955d
- https://git.kernel.org/stable/c/efa58aeb6a99028b1fbc3ab2f31ba3a881211ad4