Improper resource shutdown or release in Linux kernel - CVE-2026-74376
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown or release in the md/raid10 discard handling logic when reusing an r10bio for discard operations. A local user can trigger discard operations on a reused r10bio to cause a denial of service.
The issue occurs when a discard reuses an r10bio that was previously used for a read, leaving read_slot non-negative and causing cleanup to skip releasing the replacement bio.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-74376
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/3cb2a606ce4902eceabe68338df0653312f861f8
- https://git.kernel.org/stable/c/561c9711e4f545d6464a023168bdee03b00fa945
- https://git.kernel.org/stable/c/6b8a26af065ddc93de2aa5c9f0df98dce9723442
- https://git.kernel.org/stable/c/742e4afd247d9c972695227716b03d432a7e1d26
- https://git.kernel.org/stable/c/b7313f23ea5a79b199a007bfad64a866cc2c22e7
- https://git.kernel.org/stable/c/ce3030e92f14362880055de5fe3c258971118853
- https://git.kernel.org/stable/c/eb04e3e9c14ed15914f5fd2eae8b6435f54f095f