CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74696

highCVSS 7.5covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for. This only shows up with SO_REUSEPORT listener migration, where closing a listener hands its still-pending TFO children over to a surviving one. fastopenq.qlen is charged in tcp_fastopen_create_child() when the child is created and uncharged in reqsk_fastopen_remove() when the handshake completes. The uncharge follows rsk_listener of the request the child points at, and inet_reqsk_clone() has repointed the child at a new request owned by the new listener, so the ++ and the -- land on two different sockets. The new listener's qlen drifts negative and its limit no longer binds. Charge the new listener during migration, like reqsk_queue_migrated() already does for queue->young and queue->qlen.

CSIRTS triage

What
TCP Fast Open max_qlen accounting fails across reuseport migration, allowing resource exhaustion.
Who is affected
Linux systems with TCP Fast Open and reuseport enabled.
Urgency
Medium priority; not currently exploited but affects availability.
Action
Apply kernel patch for tcp TFO accounting fix.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74696

Get an email if CVE-2026-74696 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74696

CVE.org record

Embed the live status

CVE-2026-74696 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74696 status](https://www.csirts.com/badge/CVE-2026-74696)](https://www.csirts.com/cve/CVE-2026-74696)