Use-after-free in Linux kernel - CVE-2026-74575

 

Use-after-free in Linux kernel - CVE-2026-74575

Published: August 16, 2026


Vulnerability identifier: #VU143193
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74575
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in the thunderbolt xdomain delayed work handling in tb_xdp_handle_request() and update_xdomain() when queuing delayed work concurrently with xdomain disconnect and removal. A local user can trigger crafted xdomain requests or state changes during disconnect to cause a denial of service.

The issue arises because the request handler runs on the system workqueue and is no longer serialized with the remove path.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74575

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins