SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74704

HIGH · CVSS 8.2 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's sch_cake ACK filter, which improperly handles malformed IP headers, potentially leading to excessive warning messages in the system log or a system panic if configured to do so. While the existing code skips the problematic packets, the unnecessary WARN_ON(1) could disrupt system stability. Linux system administrators and developers utilizing the sch_cake queueing discipline should prioritize addressing this issue to enhance system reliability.

CVE
CVE-2026-74704
Severity
HIGH
CVSS
8.2
EPSS
0.44%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.