Answer in brief
CVE-2026-74678 records a High severity (CVSS 7.5) vulnerability in net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b || >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <1c63303659a2264bd55d9813df74cb4caeed5922 || >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <2be5091fa693b9119ad25a8bb8c149d236a23ade || >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <58733b1dd46bb231d9d279c132a20ee46da1b664 || >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <4039cd807a5a46dc5f7618fffae926b8ad8455eb || >=16b1c4e01c89ba07367461e0bc4cb84993c2d027 <1f428e30947395d9b9aacee03e25a4e6cfcad7a4 | 83a765cbd7b4d11b0b9fa1bb9d941ae911a2159b, 1c63303659a2264bd55d9813df74cb4caeed5922, 2be5091fa693b9119ad25a8bb8c149d236a23ade, 58733b1dd46bb231d9d279c132a20ee46da1b664, 4039cd807a5a46dc5f7618fffae926b8ad8455eb, 1f428e30947395d9b9aacee03e25a4e6cfcad7a4 |
| Linux/Linuxgeneric | 5.17 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() When the interface has NETIF_F_SG enabled and skb_linearize() fails in ax88179_tx_fixup(), the function returns NULL without freeing the skb. usbnet_start_xmit() treats a NULL return from tx_fixup() as a drop (info->flags does not set FLAG_MULTI_PACKET for this driver), jumping to the "drop" label where it does `if (skb) dev_kfree_skb_any(skb)`. Because tx_fixup() returned NULL, the local skb variable in usbnet_start_xmit() is NULL, so the original skb is never freed — a memory leak on every TX frame whose linearization fails (i.e. under memory pressure). Free the skb before returning, matching the error handling already used for the pskb_expand_head() failure path in the same function.
Quoted source text, attributed separately from HOL analysis.