PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74464 Linux CVE debrief

A vulnerability in the Linux kernel has been resolved, related to net: openvswitch. The issue involves a skb leak on flow key update failure during ct. The problem arises from ovs_ct_execute() stealing or freeing the skb on failure, while ovs_flow_key_update() does not. This results in a leaked skb if ovs_flow_key_update() fails and the function returns immediately. The fix involves breaking instead of returning and letting the common error handling code at the bottom of the loop free the skb properly. This scenario is highly unlikely as it requires a packet to become unparseable after applying a set of actions on a previously parseable skb.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel maintainers, Linux distribution vendors, and users of Linux kernel versions affected by this vulnerability. They should review and apply the fix for the skb leak issue in the Linux kernel, monitor Linux kernel updates for related patches, and perform inventory checks for affected Linux kernel versions. The vulnerability has a medium priority for Linux kernel maintainers and users, as the scenario is unlikely but should be fixed nevertheless. The issue requires a packet to become unparseable by applying a set of actions on a previously parseable skb, but should be fixed nevertheless. This fix is related to net: openvswitch in the Linux kernel, and involves a skb leak on flow key update failure during ct. The problem arises from ovs_ct_execute() stealing or freeing the skb on failure, while ovs_flow_key_update() does not. This results in a leaked skb if ovs_flow_key_update() fails and the function returns immediately. The fix involves breaking instead of returning and letting the common error handling code at the bottom of the loop free the skb properly. This is a very unlikely scenario as it requires the packet to become unparseable by applying a set of actions on a previously parseable skb, but should be fixed nevertheless. Reported by Sashiko. This issue was resolved in the Linux kernel, related to net: openvswitch. The issue involves a skb leak on flow key update failure during ct. The problem arises from ovs_ct_execute() stealing or freeing the skb on failure, while ovs_flow_key_update() does not. This results in a leaked skb if ovs_flow_key_update() fails and the function returns immediately. The fix involves breaking instead of returning and letting the common error handling code at the bottom of the loop free the skb properly. This scenario is highly unlikely as it requires a packet to become unparseable after applying a set of actions on a previously parseable skb, but should be fixed nevertheless. Reported by Sashiko. The fix involves modifying the error handling to properly free the skb. Linux kernel maintainers and users should verify affected scope and apply the fix. The vulnerability has a medium priority for Linux kernel maintainers and

Technical summary

The vulnerability is related to the net: openvswitch component in the Linux kernel. A skb leak occurs on flow key update failure during ct. The issue arises from the difference in handling skb between ovs_ct_execute() and ovs_flow_key_update(). The fix involves modifying the error handling to properly free the skb. This scenario is highly unlikely as it requires a packet to become unparseable after applying a set of actions on a previously parseable skb.

Defensive priority

Medium priority for Linux kernel maintainers and users, as the scenario is unlikely but should be fixed nevertheless.

Recommended defensive actions

  • Review and apply the fix for the skb leak issue in the Linux kernel
  • Monitor Linux kernel updates for related patches
  • Perform inventory checks for affected Linux kernel versions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence from the Linux kernel source and NVD detail. The CVE record and NVD entry provide information on the vulnerability and its resolution. The issue arises from the difference in handling skb between ovs_ct_execute() and ovs_flow_key_update(). A skb leak occurs on flow key update failure during ct. The fix involves modifying the error handling to properly free the skb. Linux kernel maintainers and users should verify affected scope and apply the fix.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74464 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74464

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74464 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74464

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/393f3c72600ab6721d732a0ab245bc896c5b28fc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/736e972f3f8a304158345223ac6e816166a467ce

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bc62e843bc48f933da765ce47079fd992e535794

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e0ba8eaef2a0d02a7a485e6a7157e47272b65cea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e84dfaac50aab45ad8c670da43e3aa1f97bd2a41

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.