Race condition in Linux kernel - CVE-2026-74555
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the libsas resume handling for hisi_sas controllers when resuming the host adapter while disks are still waking up. A local user can trigger a suspend and resume sequence to cause a denial of service.
The issue can result in I/O failures and disks being disabled during resume.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74555
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/3dbbbf656b850c9c8de05df6ad4a1dfc6ff02845
- https://git.kernel.org/stable/c/9e24b47ef81d43b3fb1b14294f09991640c79fcc
- https://git.kernel.org/stable/c/b9c44a14062093e9fc2d6bddc696cfceadb482d7
- https://git.kernel.org/stable/c/c391b5899dd46485a5893696c12ae3e95a3a7325
- https://git.kernel.org/stable/c/e50a6523a603594a6d92cdecfe11997d639410a3