Use-after-free in Linux kernel - CVE-2026-74574
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock and use-after-free in idxd_cdev_open() when handling file-device setup failures. A local user can trigger a failure during device open processing to cause a denial of service.
The issue occurs in error-handling paths that can release the last file-device reference while the workqueue lock is still held.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74574
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0679c0c189d2548f00e1bac95be28e2df5c6c7f7
- https://git.kernel.org/stable/c/6e26a41c4c1a706edaaa7c7dffc6b3b945707a55
- https://git.kernel.org/stable/c/778ccbded2c8749c5be7f0dfa04fc9977a36fb7e
- https://git.kernel.org/stable/c/8d5d28285728be47c82fdf1c48be4268293c90e7
- https://git.kernel.org/stable/c/ee1d7274102285d78a53161fc705a8d8cd40b066