PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74397 Linux CVE debrief

A vulnerability in the Linux kernel has been resolved, involving a transport domain rollback and initialization of the lb mutex. The issue arises in mlx5_ib_alloc_transport_domain(), which allocates a transport domain and then may fail in mlx5_ib_enable_lb(), leading to a potential leak of the allocated transport domain. This vulnerability affects Linux kernel deployments, and maintainers, developers, and users should assess exposure and apply patches. The patch or fix should be verified to prevent potential transport domain leaks.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel maintainers, developers, and users who need to assess exposure and apply patches to prevent potential transport domain leaks. Affected operator, platform, vulnerability-management, and security-team impact should be considered. Exposure in Linux kernel deployments should be assessed, and the patch or fix provided by the Linux kernel maintainers should be applied.

Why it matters

A vulnerability in the Linux kernel has been resolved, involving a transport domain rollback and initialization of the lb mutex. Linux kernel maintainers, developers, and users should assess exposure and apply patches.

  • Verify the patch or fix has been applied to prevent potential transport domain leaks.
  • Assess exposure in Linux kernel deployments and prioritize patching.
  • Review Linux kernel patch notes and official CVE record for specific details on the vulnerability.

Technical summary

The vulnerability involves a transport domain rollback and initialization of the lb mutex in the Linux kernel. Specifically, mlx5_ib_alloc_transport_domain() allocates a transport domain and then may fail in mlx5_ib_enable_lb(), potentially leaking the allocated transport domain. Linux kernel maintainers, developers, and users should assess exposure and apply patches to prevent potential transport domain leaks. The patch or fix should be verified to prevent potential transport domain leaks. Affected versions and exposure in Linux kernel deployments should be assessed.

Defensive priority

Low

Recommended defensive actions

  • Review the Linux kernel patch notes and official CVE record for specific details on the vulnerability.
  • Verify the affected versions and assess exposure in your Linux kernel deployments.
  • Apply the patch or fix provided by the Linux kernel maintainers.
  • Verify whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the impact and affected versions require verification from the supplied official sources. The Linux kernel patch notes and official CVE record should be reviewed for specific details on the vulnerability. Affected versions and exposure in Linux kernel deployments should be assessed, and the patch or fix provided by the Linux kernel maintainers should be applied.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74397 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74397

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74397 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74397

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2c3b2667dad69d56774b79db763acb3a1bee0fc0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/37fc3cc0f924fd8d0f0cf87b92672dec75a32e57

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/65e344925fa30abf50c8de8c150b397715fa2066

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e79389115b9d27287ff6230a9750675106ed7668

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f88e12c95fc19f719e06ca1e9eb20fdad68ef61a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.