CVE-2026-74704

Source
https://cve.org/CVERecord?id=CVE-2026-74704
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74704.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74704
Downstream
Published
2026-08-22T15:33:03Z
Modified
2026-08-27T11:30:38Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS Calculator
Summary
net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
Details

In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter

The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set.

The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74704.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8b7138814f29933898ecd31dfc83e35a30ee69f5
Fixed
c1693b7844a6c06d31a565e5a494948034dfd235
Fixed
a4b52612004a5639c4bfc30ba93ba414b8326e2a
Fixed
ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3
Fixed
0c4882bff34558d8d53fb04c3e96da5c327c7dc8
Fixed
2504a76e5c0694e14e15562730e1339f2d9f9458
Fixed
cd2f1d9fe8a507c2dc86ad326fe221f121c47734
Fixed
a1ae353d8355407c1bea971d1c1af5e7f242bb7d
Fixed
2a33516f9ef59ad11844d4fc152f889449b5daf3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74704.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.19.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74704.json"