Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74691

8.8 · HIGH
Published Aug 22, 2026 EPSS 0.26% (17th pctl)

Overview

CVE-2026-74691 is a high-severity vulnerability. It was published on August 22, 2026 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

net: thunderbolt: Tear down DMA paths before stopping the rings

tbnet_tear_down() stops both rings and frees their frame buffers before

calling tb_xdomain_disable_paths(). tb_ring_stop() zeroes the ring's

descriptor base and tbnet_free_buffers() unmaps and frees the pages the

frames sit in, so by the time __tb_path_deactivate_hop() polls the hop's

'pending' bit, anything still in flight has nowhere to drain to.

The teardown sequence has been in this order since the driver was added.

The setup path has not: commit ff7cd07f3064 ("net: thunderbolt: Enable

DMA paths only after rings are enabled") moved the path enable to the end

of tbnet_connected_work() and documented why:

/* Both logins successful so enable the rings, high-speed DMA

* paths and start the network device queue.

*

* Note we enable the DMA paths last to make sure we have primed

* the Rx ring before any incoming packets are allowed to

* arrive

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74691?

CVE-2026-74691 is a high-severity vulnerability. It was published on August 22, 2026 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2026-74691?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2026-74691?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74691?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74691 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.