Linux Kernel Vulnerability in Cache Manager Callback Handling
CVE-2026-74425
What is CVE-2026-74425?
A vulnerability in the Linux kernel affects the handling of CB.InitCallBackState3 requests within the cache manager callback path. When an incoming call does not have an associated server record via the rxrpc peer's app data, the request can be misprocessed. The fix ensures that the implementation checks for the server record's presence before proceeding, allowing unmatched callback requests to be properly ignored. This enhancement maintains consistency in callback handling and improves the reliability of the cache manager service.
Affected Version(s)
Linux 39ba6af83a7f9dee3e6a7916f41a48bcbda54eba < 42e3917cdbdc3d35e191c525687a6d5427f237fd
Linux 40e8b52fe8c8ab6920ea5f59c5469b6918cce624
Linux 40e8b52fe8c8ab6920ea5f59c5469b6918cce624 < 0bd5f2786a878148190b4c7c259d01313d5f2357