NULL pointer dereference in Linux kernel - CVE-2026-74395
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a null pointer dereference in MLX5_IB_METHOD_DEVX_SUBSCRIBE_EVENT in drivers/infiniband/hw/mlx5/devx.c when handling devx subscribe-event requests and unwinding an error after eventfd acquisition fails. A local user can trigger the error path with a crafted subscribe-event request to cause a denial of service.
The issue occurs because the subscription object is linked into the pending list before fields needed by cleanup are initialized.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-74395
kernel - update to 5.10.0-331.0.0.232
bpftool - update to 5.10.0-331.0.0.232
bpftool-debuginfo - update to 5.10.0-331.0.0.232
kernel-debuginfo - update to 5.10.0-331.0.0.232
kernel-debugsource - update to 5.10.0-331.0.0.232
kernel-devel - update to 5.10.0-331.0.0.232
kernel-headers - update to 5.10.0-331.0.0.232
kernel-source - update to 5.10.0-331.0.0.232
kernel-tools - update to 5.10.0-331.0.0.232
kernel-tools-debuginfo - update to 5.10.0-331.0.0.232
kernel-tools-devel - update to 5.10.0-331.0.0.232
perf - update to 5.10.0-331.0.0.232
perf-debuginfo - update to 5.10.0-331.0.0.232
python3-perf - update to 5.10.0-331.0.0.232
python3-perf-debuginfo - update to 5.10.0-331.0.0.232
External References
- https://git.kernel.org/stable/c/1025dc2f7ba29b04b8687790fa91f9cd1a53141e
- https://git.kernel.org/stable/c/43f8f7946814c8e5f464518246fdbc69b6e32326
- https://git.kernel.org/stable/c/5100febf8e9d6c8c5ba8dc6534c6a5e3376e5989
- https://git.kernel.org/stable/c/6e15b770461eeaa0ff73934922cb670a6a9db04e
- https://git.kernel.org/stable/c/78b9589fda266c71f0f9d0c858d4fa7381a890a5
- https://git.kernel.org/stable/c/7921821fc2b19c01588311f6e7468ae5b68b1f61
- https://git.kernel.org/stable/c/9be9aca28424228586fe9211c373ebdb826ebb6c
- https://git.kernel.org/stable/c/f345e744b6b087188cde2377da5cbe9713b61353