Use-after-free in Linux kernel - CVE-2026-74518
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in allocate_file_region_entries() when handling concurrent region cache operations on a shared resv_map. A local user can trigger concurrent region_chg()/region_add()/region_del() activity on the same shared mapping to cause a denial of service.
The issue occurs in shared hugetlbfs mappings and was observed when multiple mappers accessed the same hugetlbfs inode concurrently.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74518
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/126a70bf1a08ddc9d79c471ebdaa2b08cfbab8df
- https://git.kernel.org/stable/c/587a0accc2b4fccc5cf7baf0fe34e50efde51f9c
- https://git.kernel.org/stable/c/62e1c2741a4d923d9854efd5927a6212aad7a187
- https://git.kernel.org/stable/c/ac1bb7fd45088d0db57a22ce7729f258ebd63cf5
- https://git.kernel.org/stable/c/dd9623f58ec702a07b2d67179d6fcea79c52231a