CVE-2026-74719Patch

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The SMC_LLC_CONFIRM_LINK / SMC_LLC_ADD_LINK_CONT branch in smc_llc_event_handler() stores an incoming qentry into the local LLC flow without first checking whether a qentry is already pending. If a malicious or buggy peer sends a second CONFIRM_LINK or ADD_LINK_CONT request while a flow is active and flow->qentry is already set, smc_llc_flow_qentry_set() overwrites the pointer without freeing the previous allocation, leaking one kmalloc-96 object per spurious message. The sibling SMC_LLC_DELETE_LINK branch already has the correct !flow->qentry guard. Apply the same guard to the CONFIRM_LINK/ADD_LINK_CONT branch so that a duplicate message when qentry is already occupied falls through to break and is freed by the kfree(qentry) at the out: label, rather than silently leaking the existing allocation. The response direction (smc_llc_rx_response()) is unaffected: it already guards with flow->qentry at the equivalent site and drops duplicate responses correctly.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-22: 3Patch / Workaround · 2026-08-22: 2Technical Details · 2026-08-22: 308-22
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-74719 Linux Kernel Memory Leak in smc_llc_event_handler() https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74719 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a newly identified kernel‑level memory‑leak vulnerability (CVE‑2026‑74719) in smc_llc_event_handler(), providing a reference link but no PoC, exploit, or patch information.

    00010153
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-74719 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The … https://www.cve.org/CVERecord?id=CVE-2026-74719 ----- Traducción: CVE-2026-74719 En … http://infoflow.cloud`

    Post summary

    CVE‑2026‑74719 was a Linux kernel issue involving a qentry overwrite, and it has been fixed with a patch; no exploit or PoC details are disclosed.

    0000023
    102 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-74719 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() The … https://www.cve.org/CVERecord?id=CVE-2026-74719

    Post summary

    The post announces that CVE-2026-74719, a qentry overwrite issue in the Linux kernel's smc_llc_event_handler(), has been fixed.

    00000874
    58.0K followersView on X

Explore more