CVE-2026-74704: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026082236-CVE-2026-74704-ab92@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects. The Linux kernel CVE team has assigned CVE-2026-74704 to this issue. Affected and fixed versions =========================== Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 5.10.265 with commit c1693b7844a6c06d31a565e5a494948034dfd235 Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 5.15.216 with commit a4b52612004a5639c4bfc30ba93ba414b8326e2a Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 6.1.183 with commit ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3 Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 6.6.152 with commit 0c4882bff34558d8d53fb04c3e96da5c327c7dc8 Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 6.12.104 with commit 2504a76e5c0694e14e15562730e1339f2d9f9458 Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 6.18.45 with commit cd2f1d9fe8a507c2dc86ad326fe221f121c47734 Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 7.1.9 with commit a1ae353d8355407c1bea971d1c1af5e7f242bb7d Issue introduced in 4.19 with commit 8b7138814f29933898ecd31dfc83e35a30ee69f5 and fixed in 7.2 with commit 2a33516f9ef59ad11844d4fc152f889449b5daf3 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74704 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/sched/sch_cake.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235 https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3 https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8 https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458 https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734 https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3