CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74719

lowCVSS 3.7covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking whether a qentry is already pending. If a malicious or buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the pointer without freeing the previous allocation, leaking one kmalloc-96 object per spurious message. The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a duplicate message when qentry is already occupied falls through to break and is freed by the kfree(qentry) at the out: label, rather than silently leaking the existing allocation. The response direction (smc_llc_rx_response()) is unaffected: it already guards with flow->qentry at the equivalent site and drops duplicate responses correctly.

CSIRTS triage

What
The net/smc smc_llc_event_handler function overwrites queue entries for CONFIRM_LINK and ADD_LINK_CONT messages.
Who is affected
Systems running affected Linux kernel versions with SMC protocol support.
Urgency
Low severity (CVSS 3.7); not currently exploited and has limited impact.
Action
Update to a patched Linux kernel version addressing CVE-2026-74719.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74719

Get an email if CVE-2026-74719 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74719

CVE.org record

Embed the live status

CVE-2026-74719 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74719 status](https://www.csirts.com/badge/CVE-2026-74719)](https://www.csirts.com/cve/CVE-2026-74719)