CVE-2026-74560

Description

A flaw was found in the Linux kernel's AF_XDP (Address Family eXpress Data Path) subsystem. When handling multi-buffer transmissions, the xsk_drop_skb() function incorrectly cancels completion queue (CQ) reservations without submitting buffer addresses to the CQ. This leads to a buffer leak where userspace permanently loses track of these buffers, potentially causing resource exhaustion and affecting system stability.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (Other)

An attacker that can influence the allocation of resources that are not properly maintained could deplete the available resource pool and prevent all other processes from accessing the same type of resource.

Frequently Asked Questions

Want to get errata notifications? Sign up here.