SB20260816244 - Use-after-free in Linux kernel mm
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74481)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in page_reporting_process and virtballoon_free_page_report when page reporting work continues during power management freeze while virtqueues are being deleted. A local user can trigger suspend or hibernation activity while freed pages are being reported to access deleted virtqueues and cause a denial of service.
The issue can be reached during S3 suspend or S4 hibernation, including cases where memory reclamation returns pages to the buddy allocator during image saving.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0b45f6927a14914ff685fe0e6f9d11232a1e03df
- https://git.kernel.org/stable/c/450f35f4d5a682a0796757e52295df58ddb63bc9
- https://git.kernel.org/stable/c/b11907c905fa08eda925395f0724b7a409870f65
- https://git.kernel.org/stable/c/f978048326570047e8216e81a67f9c71ef2bb1b1
- https://git.kernel.org/stable/c/faf439b5fa7b231120eac4f7a617e0bfd4f6f5c7