Missing Release of Resource after Effective Lifetime in Linux kernel - CVE-2026-74514
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in KVM s390 PCI memory accounting functions when accounting and unaccounting pinned pages. A local user can trigger page pinning and unpinning operations to cause a denial of service.
The issue can be triggered when unaccounting occurs in a different process context than the one that originally pinned the pages.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74514
linux (Debian package) - update to 6.12.105-1