Answer in brief
CVE-2026-74704 records a Unknown severity vulnerability in net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <c1693b7844a6c06d31a565e5a494948034dfd235 || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <a4b52612004a5639c4bfc30ba93ba414b8326e2a || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3 || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <0c4882bff34558d8d53fb04c3e96da5c327c7dc8 || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <2504a76e5c0694e14e15562730e1339f2d9f9458 || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <cd2f1d9fe8a507c2dc86ad326fe221f121c47734 || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <a1ae353d8355407c1bea971d1c1af5e7f242bb7d || >=8b7138814f29933898ecd31dfc83e35a30ee69f5 <2a33516f9ef59ad11844d4fc152f889449b5daf3 | c1693b7844a6c06d31a565e5a494948034dfd235, a4b52612004a5639c4bfc30ba93ba414b8326e2a, ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3, 0c4882bff34558d8d53fb04c3e96da5c327c7dc8, 2504a76e5c0694e14e15562730e1339f2d9f9458, cd2f1d9fe8a507c2dc86ad326fe221f121c47734, a1ae353d8355407c1bea971d1c1af5e7f242bb7d, 2a33516f9ef59ad11844d4fc152f889449b5daf3 |
| Linux/Linuxgeneric | 4.19 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.
Quoted source text, attributed separately from HOL analysis.