Kernel Vulnerability in Linux Affecting Multi-Packet WQE Path
CVE-2026-74709

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74709?

A vulnerability in the Linux kernel allows user space to manipulate metadata flags following request processing. This can lead to scenarios where the kernel erroneously writes a timestamp that was never requested during the packet submission process. The issue arises particularly in the mlx5 multi-packet WQE path, where the metadata pointer is not cleared unless a timestamp is explicitly requested. Consequently, completion handlers may inaccurately record timestamps for descriptors in a session, creating potential discrepancies in packet processing and security vulnerabilities. The problem is limited to specific paths and versions, emphasizing the need for awareness and timely updates to safeguard against unauthorized metadata handling.

Affected Version(s)

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 0ba2e1eb07a826d021344e2f146b6716c58139eb

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0

Linux ca4419f15abd19ba8be1e109661b60f9f5b6c9f0 < 9f60a67df8d3c862503bee62bada8e7089cba438

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.