Linux Kernel devlink netns ref leak in reload
CVE-2026-74718 Published on August 22, 2026
devlink: fix net namespace reference leak in reload
In the Linux kernel, the following vulnerability has been resolved:
devlink: fix net namespace reference leak in reload
devlink_nl_reload_doit() calls devlink_netns_get(), which returns a net
with a held reference. When the requested namespace differs from the
current one and the reload action is not DRIVER_REINIT, the function
returns -EOPNOTSUPP without releasing the reference. Add the missing
put_net() on this error path.
Products Associated with CVE-2026-74718
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 2edd92570441dd33246210042dc167319a5cf7e3 and below 7b6552e53426ea0539c667bbc5a524fdf7feae6f is affected.
- Version 2edd92570441dd33246210042dc167319a5cf7e3 and below bf0797b92be591ac71d7c0f610e695caca3c72c9 is affected.
- Version 2edd92570441dd33246210042dc167319a5cf7e3 and below 7b02c6d2a3cd2cd669f5c16685779f84328ae60c is affected.
- Version 2edd92570441dd33246210042dc167319a5cf7e3 and below eda60c85b4f4c7d66b7141a5fe020b1a7f395341 is affected.
- Version 2edd92570441dd33246210042dc167319a5cf7e3 and below 1c4dac9bf1d2ac31da63b794bdec697777cbd0fd is affected.
- Version 6.3 is affected.
- Before 6.3 is unaffected.
- Version 6.6.152, <= 6.6.* is unaffected.
- Version 6.12.104, <= 6.12.* is unaffected.
- Version 6.18.45, <= 6.18.* is unaffected.
- Version 7.1.9, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.