CVE-2026-74704
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0c4882bff34558d8d53fb04c3e96da5c327c7dc8
- https://git.kernel.org/stable/c/2504a76e5c0694e14e15562730e1339f2d9f9458
- https://git.kernel.org/stable/c/2a33516f9ef59ad11844d4fc152f889449b5daf3
- https://git.kernel.org/stable/c/a1ae353d8355407c1bea971d1c1af5e7f242bb7d
- https://git.kernel.org/stable/c/a4b52612004a5639c4bfc30ba93ba414b8326e2a
- https://git.kernel.org/stable/c/ae1b2f8e21a41e7c7e75511bea0c4ccc59ec1bd3
- https://git.kernel.org/stable/c/c1693b7844a6c06d31a565e5a494948034dfd235
- https://git.kernel.org/stable/c/cd2f1d9fe8a507c2dc86ad326fe221f121c47734
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.