CVE-2026-74718

Source
https://cve.org/CVERecord?id=CVE-2026-74718
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74718.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74718
Downstream
Published
2026-08-22T15:33:12Z
Modified
2026-08-24T11:47:21Z
Summary
devlink: fix net namespace reference leak in reload
Details

In the Linux kernel, the following vulnerability has been resolved:

devlink: fix net namespace reference leak in reload

devlink_nl_reload_doit() calls devlink_netns_get(), which returns a net with a held reference. When the requested namespace differs from the current one and the reload action is not DRIVER_REINIT, the function returns -EOPNOTSUPP without releasing the reference. Add the missing put_net() on this error path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74718.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2edd92570441dd33246210042dc167319a5cf7e3
Fixed
7b6552e53426ea0539c667bbc5a524fdf7feae6f
Fixed
bf0797b92be591ac71d7c0f610e695caca3c72c9
Fixed
7b02c6d2a3cd2cd669f5c16685779f84328ae60c
Fixed
eda60c85b4f4c7d66b7141a5fe020b1a7f395341
Fixed
1c4dac9bf1d2ac31da63b794bdec697777cbd0fd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74718.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.3.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74718.json"