SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74696

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's TCP Fast Open implementation, specifically during the migration of listeners using the SO_REUSEPORT option. This flaw allows a listener to inaccurately account for the maximum number of pending Fast Open requests, potentially exceeding its configured limit and leading to resource exhaustion or denial of service. System administrators and developers managing Linux-based servers with TCP Fast Open enabled should prioritize addressing this issue to ensure reliable network performance and security.

CVE
CVE-2026-74696
Severity
HIGH
CVSS
7.5
EPSS
0.49%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for. This only shows up with SO_REUSEPORT listener migration, where closing a listener hands its still-pending TFO children over to a surviving one. fastopenq.qlen is charged in tcp_fastopen_create_child() when the child is created and uncharged in reqsk_fastopen_remove() when the handshake completes. The uncharge follows rsk_listener of the request the child points at, and inet_reqsk_clone() has repointed the child at a new request owned by the new listener, so the ++ and the -- land on two different sockets. The new listener's qlen drifts negative and its limit no longer binds. Charge the new listener during migration, like reqsk_queue_migrated() already does for queue->young and queue->qlen.