SB20260816244 - Use-after-free in Linux kernel mm



SB20260816244 - Use-after-free in Linux kernel mm

Published: August 16, 2026

Security Bulletin ID SB20260816244
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Use-after-free (CVE-ID: CVE-2026-74481)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in page_reporting_process and virtballoon_free_page_report when page reporting work continues during power management freeze while virtqueues are being deleted. A local user can trigger suspend or hibernation activity while freed pages are being reported to access deleted virtqueues and cause a denial of service.

The issue can be reached during S3 suspend or S4 hibernation, including cases where memory reclamation returns pages to the buddy allocator during image saving.


Remediation

Install update from vendor's website.