Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-74623— net: atlantic: free stranded TX buffers on ring deinit

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: 网络驱动:atlantic —— 在环形队列注销时释放残留的 TX 缓冲区 通过单次调用 来排空 TX 环形队列。该函数最多释放 (256)个描述符,并在 (硬件头部指针)处停止,而一旦 停止了硬件和 NAPI(网络轮询接口), 就不再移动。因此,超出预算的已完成描述符,以及仍保留在 区间内的所有条目,在接口关闭时仍保留其 或 。随后 会释放缓冲区环形队列本身,导致这些引用永久丢失。 当前,在每次接口关闭(ifdown)且存在 TX/XDP_TX 负载时,都会发生静默内存泄

AI Predicted 5.3 Difficulty: Moderate EPSS 0.18% · P7

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux eb36bedf28be6d986bdbcfa375bab08ffa45efd8< a14ceebd13bf857bfca052bc5a6bd49e737912be affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< 4f1c20873f70b4b22ef86dc38dad1fda8e169bcd affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< 307d80193b4a4a75b8dc4e0d3162be3755abbed7 affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< 7a3e1481f4ee6c581bccc6bfc6c970aac5be7b0c affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< 3447641d361dcc5511841d986ad4d849b2900d9b affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< b13202d401e1a20fec89b0cda733dcbaf279f79d affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< dd633280de7fdfd60dc4fcf63d04e2ad95b43269 affected
eb36bedf28be6d986bdbcfa375bab08ffa45efd8< 452636ea5410a96e02ebaaf80b21e3620b98e0dd affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-74623

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: atlantic: free stranded TX buffers on ring deinit
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: atlantic: free stranded TX buffers on ring deinit aq_vec_deinit() drains the TX rings with a single aq_ring_tx_clean() call, which frees at most AQ_CFG_TX_CLEAN_BUDGET (256) descriptors and stops at hw_head, which no longer moves once aq_vec_stop() has stopped the hardware and NAPI. Completed descriptors beyond the budget and everything still posted in [hw_head, sw_tail) keep their skb or xdp_frame when the interface goes down: aq_vec_ring_free() then frees the buffer ring and the references are lost for good. Today this is a silent memory leak on every interface down under TX/XDP_TX load. With the conversion of the RX path to page_pool posted for net-next it becomes much more visible: XDP_TX frames carry fragment references on the RX ring's page_pool, so a single stranded frame keeps the pool's inflight count above zero forever. page_pool_destroy() then never completes, the pool is leaked together with its pages, and "page_pool_release_retry() stalled pool shutdown" is warned every 60 seconds from that point on, on every ifdown, XDP detach or ring resize under XDP_TX load. Bring back aq_ring_tx_deinit() as it was before the removal and use it for teardown again, with one extension: TX rings can hold xdp_frames nowadays, so release those too. They are returned with xdp_return_frame() since this runs in process context.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux eb36bedf28be6d986bdbcfa375bab08ffa45efd8 ~ a14ceebd13bf857bfca052bc5a6bd49e737912be -
Linux Linux 4.11 -

II. Public POCs for CVE-2026-74623

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-74623

登录查看更多情报信息。

Patches & Fixes for CVE-2026-74623 (8)

Same Patch Batch · Linux · 2026-08-22 · 150 CVEs total

CVE-2026-74705 10.0 CRITICAL udp: fix potential use-after-free in tunnel segmentation
CVE-2026-74612 10.0 CRITICAL veth: fix skb length accounting after XDP frag adjustment
CVE-2026-74616 9.8 CRITICAL xdp: reject clones that overrun skb_shared_info tailroom
CVE-2026-74617 9.8 CRITICAL dibs: initialise dibs->lock in dibs_dev_alloc()
CVE-2026-74597 9.8 CRITICAL ip6_tunnel: clear skb2->cb[] in ip6ip6_err()
CVE-2026-74688 9.8 CRITICAL sctp: clear control chunk transport if it is being removed
CVE-2026-74608 9.8 CRITICAL smb: client: Fix use-after-free in cifs_try_adding_channels()
CVE-2026-74669 9.8 CRITICAL ipvs: clear IPv4 options after rebasing tunnel ICMP errors
CVE-2026-74662 9.8 CRITICAL inet: frags: publish queues before arming timer
CVE-2026-74591 9.8 CRITICAL mm/filemap: __filemap_add_folio() restore index before retrying
CVE-2026-74628 9.8 CRITICAL net/x25: fix use-after-free of the socket by its timers
CVE-2026-74587 9.8 CRITICAL sctp: fix use-after-free of cached ASCONF chunk
CVE-2026-74588 9.8 CRITICAL sctp: keep chunk->transport in step with the list it is queued on
CVE-2026-74730 9.8 CRITICAL NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
CVE-2026-74727 9.8 CRITICAL ovpn: skip rehash for peers already removed from by_id
CVE-2026-74611 9.8 CRITICAL tls: rx: restore msg_iter before TLS 1.3 optimistic retry
CVE-2026-74586 9.8 CRITICAL sctp: clear new_transport when removing a peer
CVE-2026-74723 9.8 CRITICAL btrfs: lzo: reject inline extents without valid headers
CVE-2026-74712 9.3 CRITICAL vdpa/mlx5: Fix buffer length in create_direct_keys()
CVE-2026-74665 9.1 CRITICAL net: fix skb length accounting after generic XDP frag adjustment

Showing top 20 of 150 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-74623

No comments yet


Leave a comment