In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stopping the rings… (CVE-2026-74691)
A vulnerability in the Linux kernel's thunderbolt network driver (tbnet) involves an incorrect teardown sequence of DMA paths and rings. The teardown process stops rings and frees buffers before disabling DMA paths, causing the 'pending' bit to never clear on some hardware, leading to timeouts and eventual loss of the XDomain control channel. This can cause the peer node to become unreachable until a power cycle is performed. The issue is fixed by changing the teardown order to deactivate DMA paths before stopping the rings.
AI Analysis
Technical Summary
The Linux kernel thunderbolt network driver (tbnet) had a teardown sequence flaw where DMA paths were disabled after stopping the rings and freeing buffers. This order mismatch with the setup sequence caused the 'pending' bit in __tb_path_deactivate_hop() to never clear on certain hardware (e.g., ASMedia ASM4242 host router), resulting in repeated teardown timeouts (-ETIMEDOUT) and eventual loss of the XDomain control channel. The failure is silent above the thunderbolt core, and repeated failures require a power cycle to restore functionality. Changing the teardown sequence to deactivate DMA paths before stopping rings resolves the issue, eliminating timeouts and preventing link failures without affecting throughput or latency.
Potential Impact
On affected hardware, repeated network interface teardowns can fail silently due to the 'pending' bit never clearing, causing timeouts and eventual loss of the XDomain control channel. This leads to the peer node becoming unreachable and requires a power cycle to recover the controller. Hosts with routers that properly drain the hop do not experience functional differences. There is no indication of remote code execution or data leakage, but network connectivity can be disrupted until manual intervention.
Mitigation Recommendations
A fix is available that changes the teardown sequence to deactivate DMA paths before stopping the rings, resolving the timeout and link failure issue. Users should update to a Linux kernel version that includes this fix. Since the vulnerability is in the Linux kernel driver, applying the official kernel update or patch that addresses CVE-2026-74691 is the recommended remediation. No other mitigations are indicated.
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Tear down DMA paths before stopping the rings… (CVE-2026-74691)
Description
A vulnerability in the Linux kernel's thunderbolt network driver (tbnet) involves an incorrect teardown sequence of DMA paths and rings. The teardown process stops rings and frees buffers before disabling DMA paths, causing the 'pending' bit to never clear on some hardware, leading to timeouts and eventual loss of the XDomain control channel. This can cause the peer node to become unreachable until a power cycle is performed. The issue is fixed by changing the teardown order to deactivate DMA paths before stopping the rings.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel thunderbolt network driver (tbnet) had a teardown sequence flaw where DMA paths were disabled after stopping the rings and freeing buffers. This order mismatch with the setup sequence caused the 'pending' bit in __tb_path_deactivate_hop() to never clear on certain hardware (e.g., ASMedia ASM4242 host router), resulting in repeated teardown timeouts (-ETIMEDOUT) and eventual loss of the XDomain control channel. The failure is silent above the thunderbolt core, and repeated failures require a power cycle to restore functionality. Changing the teardown sequence to deactivate DMA paths before stopping rings resolves the issue, eliminating timeouts and preventing link failures without affecting throughput or latency.
Potential Impact
On affected hardware, repeated network interface teardowns can fail silently due to the 'pending' bit never clearing, causing timeouts and eventual loss of the XDomain control channel. This leads to the peer node becoming unreachable and requires a power cycle to recover the controller. Hosts with routers that properly drain the hop do not experience functional differences. There is no indication of remote code execution or data leakage, but network connectivity can be disrupted until manual intervention.
Mitigation Recommendations
A fix is available that changes the teardown sequence to deactivate DMA paths before stopping the rings, resolving the timeout and link failure issue. Users should update to a Linux kernel version that includes this fix. Since the vulnerability is in the Linux kernel driver, applying the official kernel update or patch that addresses CVE-2026-74691 is the recommended remediation. No other mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-m57c-v73h-37p6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74691"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a8a27f1acd9273b499bc756
Added to database: 08/22/2026, 22:51:29 UTC
Last enriched: 08/23/2026, 00:25:13 UTC
Last updated: 08/23/2026, 01:52:13 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.