Junglewise Threat Intelligence

CVE-2026-74691: Linux kernel Thunderbolt network DMA path teardown denial of service

CVE-2026-74691 · Severity: high · CVSS 8.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Thunderbolt networking driver has a bug in how it tears down network connections that can cause the system to hang during disconnection. When stopping a Thunderbolt network interface, the driver shuts down the network rings before properly deactivating the DMA data paths, leaving in-flight data with nowhere to drain. This causes the teardown process to timeout and potentially kill the Thunderbolt control channel, requiring a power cycle to restore connectivity.

Technical details

The vulnerability is a resource management and sequencing bug in the Thunderbolt network driver's teardown path. The tbnet_tear_down() function stops the DMA rings and frees their frame buffers before calling tb_xdomain_disable_paths(), which reverses the setup order documented in the codebase. This causes in-flight DMA transfers to have no valid descriptor base to drain to, resulting in __tb_path_deactivate_hop() timing out (500+ ms) waiting for the hop's 'pending' bit to clear. The condition affects all Thunderbolt network teardowns on affected hardware (e.g., ASMedia ASM4242 routers) and is particularly critical because the failure path is silent—the error is not propagated up the call stack, and repeated failed teardowns eventually take down the XDomain control channel entirely, requiring a power cycle. The fix involves reversing the teardown order to deactivate DMA paths before stopping the rings, mirroring the setup sequence.

Affected products

  • Linux Linux kernel prior to fix (affects Thunderbolt networking driver in net/thunderbolt)

Timeline

  • 2026-08-22: disclosed

Related threats