CVE EVIDENCE REVIEW
ReviewHighEvidence review

CVE-2026-74523 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: qede: sync udp_tunnel ports outside qede_lock in the recovery path A TX timeout on a qede NIC that has VXLAN/GENEVE tunnel ports configured wedges the rtnetlink control plane of the whole machine: NETDEV WATCHDOG: ens6f1 (qede): transmit queue 2 timed out 10226 ms [qede_tx_timeout:586(ens6f1)]TX timeout on queue 2! [qede_recovery_handler:2665(ens6f0)]Starting a recovery process The recovery path deadlocks on the driver's own mutex: qede_sp_task rtnl_lock() mutex_lock(&edev->qede_lock) <- taken qede_recovery_handler qede_loa...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 19e505ee8bb9e0f0355eda9e9f614fb25fed0070, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < c4c1e5d6bc2b900b2328d6fff93dc8146b858d69, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 8e1bdf57de91247e57816482966265ada573cc74, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < e382a4efeeae6555b95d9ff336cf3094ee7d336b, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 4626df3f63c9185efba5750fe76ac01ab3351bae, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < e51becb8f3377a377171ed5bf0082b96e22e6292, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 451c9075d6c53f2438d110addbeeeea6fac18567, >= 5.9
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 7.5 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 19e505ee8bb9e0f0355eda9e9f614fb25fed0070, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < c4c1e5d6bc2b900b2328d6fff93dc8146b858d69, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 8e1bdf57de91247e57816482966265ada573cc74, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < e382a4efeeae6555b95d9ff336cf3094ee7d336b, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 4626df3f63c9185efba5750fe76ac01ab3351bae, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < e51becb8f3377a377171ed5bf0082b96e22e6292, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 6f1ef8170d3d8ad9319aa01347945dcdf5cc4f27, >= 8cd160a29415f1789d473b1dc07fcc9d02a02b87 < 451c9075d6c53f2438d110addbeeeea6fac18567, >= 5.9. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.