« Volver al listado

CVE-2026-74704

Estado: RecibidaAlta (8.2)—

In the Linux kernel, the following vulnerability has been resolved:

net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter

The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set.

The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Paquete malformado remoto en Linux kernel (AV:N, PR:N) causa DoS por panic o spam de logs. Vector CVSS indica red sin privilegios. T1499.004 (Denial of Service por consumo de recursos del sistema).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74704",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "c1693b7844a6c06d31a565e5a494948034dfd235",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "a4b52612004a5639c4bfc30ba93ba414b8326e2a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "0c4882bff34558d8d53fb04c3e96da5c327c7dc8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "2504a76e5c0694e14e15562730e1339f2d9f9458",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "cd2f1d9fe8a507c2dc86ad326fe221f121c47734",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "a1ae353d8355407c1bea971d1c1af5e7f242bb7d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8b7138814f29933898ecd31dfc83e35a30ee69f5",
              "lessThan": "2a33516f9ef59ad11844d4fc152f889449b5daf3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/sched/sch_cake.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/sched/sch_cake.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:45.090",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter\n\nThe sch_cake ACK filter parses packets to find the TCP header and filter\nduplicated ACKs if the flow is backlogged. The parsing code contains a\nWARN_ON(1) which can be triggered by a malformed IP header in certain\ncases. Depending on the system configuration, this leads either to\neither spamming dmesg with warnings, or a panic if panic_on_warn is set.\n\nThe code already correctly skips the offending packet in the branch that\ntriggers the warning, so the WARN_ON itself doesn't really serve any\npurpose. So just drop it altogether to avoid the inconvenient side\neffects."
    }
  ],
  "lastModified": "2026-08-25T06:18:54.583",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}