{"api_version":"1","generated_at":"2026-08-23T21:53:22+00:00","cve":"CVE-2026-74626","urls":{"html":"https://cve.report/CVE-2026-74626","api":"https://cve.report/api/cve/CVE-2026-74626.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74626","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74626"},"summary":{"title":"NTB: ntb_netdev: Preserve RX queue depth on allocation failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-22 16:16:35","updated_at":"2026-08-23 13:16:47"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd","name":"https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540","name":"https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517","name":"https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74626","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74626","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 548c237c0a9972df5d1afaca38aa733ee577128d a4e340971fe8ccd245d206db4d43b2a0eec240bd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 548c237c0a9972df5d1afaca38aa733ee577128d 755fd7843f300d724caceabdf9bb13adc8701540 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 548c237c0a9972df5d1afaca38aa733ee577128d d2121faf133ac3bf9531b53a7e21273649a08517 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.46 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.9 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ntb_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a4e340971fe8ccd245d206db4d43b2a0eec240bd","status":"affected","version":"548c237c0a9972df5d1afaca38aa733ee577128d","versionType":"git"},{"lessThan":"755fd7843f300d724caceabdf9bb13adc8701540","status":"affected","version":"548c237c0a9972df5d1afaca38aa733ee577128d","versionType":"git"},{"lessThan":"d2121faf133ac3bf9531b53a7e21273649a08517","status":"affected","version":"548c237c0a9972df5d1afaca38aa733ee577128d","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ntb_netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.9"},{"lessThan":"3.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.46","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.9","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"3.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.9","versionStartIncluding":"3.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"3.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again."}],"providerMetadata":{"dateUpdated":"2026-08-23T12:47:50.773Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a4e340971fe8ccd245d206db4d43b2a0eec240bd"},{"url":"https://git.kernel.org/stable/c/755fd7843f300d724caceabdf9bb13adc8701540"},{"url":"https://git.kernel.org/stable/c/d2121faf133ac3bf9531b53a7e21273649a08517"}],"title":"NTB: ntb_netdev: Preserve RX queue depth on allocation failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74626","datePublished":"2026-08-22T15:32:08.687Z","dateReserved":"2026-08-15T05:44:03.921Z","dateUpdated":"2026-08-23T12:47:50.773Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-22 16:16:35","lastModifiedDate":"2026-08-23 13:16:47","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74626","Ordinal":"1","Title":"NTB: ntb_netdev: Preserve RX queue depth on allocation failure","CVE":"CVE-2026-74626","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74626","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_netdev: Preserve RX queue depth on allocation failure\n\nntb_netdev_rx_handler() hands the received skb to the network stack\nbefore allocating its replacement. If the allocation fails, nothing is\nreposted. Every failure therefore takes one buffer out of the RX queue\nwhile the interface remains up, and enough failures eventually stall\nreception.\n\nA retry path could refill the queue later, but ntb_netdev has none.\nAllocate the replacement first instead. If that fails, drop the packet\nand repost the same skb. This keeps the queue full and lets packet\ndelivery resume as soon as memory is available again.","Type":"Description","Title":"NTB: ntb_netdev: Preserve RX queue depth on allocation failure"}]}}}