CVE-2026-74725

Source
https://cve.org/CVERecord?id=CVE-2026-74725
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74725.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74725
Downstream
Published
2026-08-22T15:33:16Z
Modified
2026-08-27T11:30:50Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
enic: fix tx_hang_reset use-after-free on device removal
Details

In the Linux kernel, the following vulnerability has been resolved:

enic: fix tx_hang_reset use-after-free on device removal

enic_remove() cancels the reset and change_mtu_work items but does not cancel tx_hang_reset. A TX timeout that fires while the device is being removed can schedule enic_tx_hang_reset() so that it runs after free_netdev(), resulting in a use-after-free.

cancel_work_sync() alone is not sufficient here: the still-live watchdog and notify paths can re-schedule these work items in the window between the cancel and unregister_netdev(). Use disable_work_sync(), which cancels the work and blocks any subsequent schedule_work() from requeuing it, and apply it to the reset and change_mtu_work items as well so the same requeue race is closed for all teardown work.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74725.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
937317c7c1097aa878a5000e3aab616eb5c590c0
Fixed
8619865f34fb3b130b567855382a5c4aadd522b9
Fixed
e506e704b74748ffd0e1c92a7453ca2a959f832b
Fixed
4f3464fc6c1f26afc504fd525c574f2bc14c9d42
Fixed
ec680ea4ba1bca92a767fb7e7869758bfdd886e3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74725.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74725.json"