CVE EVIDENCE REVIEW
ReviewHighEvidence review

CVE-2026-74429 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the reception of a reply packet before data transmission Fix rxrpc_receiving_reply() to handle the reception of an apparent reply DATA packet before rxrpc has had a chance to send any request DATA packets on a client call by checking to see if the call has been exposed yet by sending the first packet. Without this, rxrpc_rotate_tx_window() might oops. Also fix rxrpc_rotate_tx_window() to handle the Tx queue being empty by changing the do...while loop into a while loop, just in case a call is abnormally terminated...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= b341a0263b1b804d329f864c2dc24815364510ec < f9be514984471ff0003738b2e1efed12bc3433ff, >= b341a0263b1b804d329f864c2dc24815364510ec < e220ae559e5a0fc33e41ec6a348ea50387cb8b0f, >= b341a0263b1b804d329f864c2dc24815364510ec < a58e33405acd2584e730c1da72635f822ada6b49, >= 6.14
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 7.5 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= b341a0263b1b804d329f864c2dc24815364510ec < f9be514984471ff0003738b2e1efed12bc3433ff, >= b341a0263b1b804d329f864c2dc24815364510ec < e220ae559e5a0fc33e41ec6a348ea50387cb8b0f, >= b341a0263b1b804d329f864c2dc24815364510ec < a58e33405acd2584e730c1da72635f822ada6b49, >= 6.14. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.