Security Advisory

CVE-2026-74704

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-22 15:33:03
Last updated 2026-08-25 05:41:47
Assigner Linux
CVSS score 8.2
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_cake: drop WARN_ON(1) for malformed packets in ACK filter The sch_cake ACK filter parses packets to find the TCP header and filter duplicated ACKs if the flow is backlogged. The parsing code contains a WARN_ON(1) which can be triggered by a malformed IP header in certain cases. Depending on the system configuration, this leads either to either spamming dmesg with warnings, or a panic if panic_on_warn is set. The code already correctly skips the offending packet in the branch that triggers the warning, so the WARN_ON itself doesn't really serve any purpose. So just drop it altogether to avoid the inconvenient side effects.