CVE-2026-74545 is a vulnerability in Linux Kernel
Published on August 15, 2026
rtase: fix double free of multi-frag skb on DMA map failure
In the Linux kernel, the following vulnerability has been resolved:
rtase: fix double free of multi-frag skb on DMA map failure
In rtase_start_xmit(), when the head buffer DMA mapping fails after
rtase_xmit_frags() has mapped all fragments, the error path clears
the fragment descriptors with rtase_tx_clear_range(), which frees
the skb through the last-frag slot and accounts tx_dropped. Control
then falls through to the common error label, which frees the same
skb a second time and counts it again.
Return right after clearing the fragments when the skb owns frags;
the no-frag case still drops through and frees the head skb once.
Products Associated with CVE-2026-74545
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version d6e882b89fdf80be0ab4f914ec10f75215e49495 and below 4f09172aff5f73a5e914f4fbc0d00a1c2ea9f7cb is affected.
- Version d6e882b89fdf80be0ab4f914ec10f75215e49495 and below db986098f30881fafcc752800aa3b13fd289c922 is affected.
- Version d6e882b89fdf80be0ab4f914ec10f75215e49495 and below de691dc3227b061c4d0beba9f0128fe1ff33dd68 is affected.
- Version d6e882b89fdf80be0ab4f914ec10f75215e49495 and below 6fb7b769d6ed6d1d2e02af4a80e57a2477f35086 is affected.
- Version 6.12 is affected.
- Before 6.12 is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.