CVE-2026-74386
CVE CVE-2026-74386EUVD EUVD-2026-59533Published 2026-08-15T05:59:01.000ZLast changed 2026-08-17T05:18:24.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix page fragment cache leak in error path In nvmet_tcp_alloc_queue(), when a connection is closed during the allocation process (e.g., nvmet_tcp_set_queue_sock() returns -ENOTCONN), the error handling jumps to out_destroy_sq and then to out_ida_remove without draining the page fragment cache. Although nvmet_tcp_free_cmd() is called in some error paths to release individual page fragments, the underlying page cache reference held by queue->pf_cache is never released. The first allocation using pf_cache is the call to nvmet_tcp_alloc_cmd() for queue->connect, which happens after ida_alloc() returns successfully. This results in a page leak each time a connection fails during allocation, which could lead to memory exhaustion over time if connections are repeatedly opened and closed. Fix this by calling page_frag_cache_drain() before freeing the queue structure in the out_ida_remove label.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 872d26a391da92ed8f0c0f5cb5fef428067b7f30 <a43a9abc1ebf663f0aa56a729106f68dd9c77da6; 872d26a391da92ed8f0c0f5cb5fef428067b7f30 <4dae393956093c807212918fd91a8fc70df15338; 872d26a391da92ed8f0c0f5cb5fef428067b7f30 <ba3209704b3cd46961e4e081af5c52a780785648; patch: 7.2; patch: 6.12.97; patch: 7.1.5; patch: 6.18.40; patch: 0; 5.0; 872d26a391da92ed8f0c0f5cb5fef428067b7f30 <5fbe83a374f09561a0f0c1f4aa021501ffd681eb
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.