Use-after-free in Linux kernel - CVE-2026-74501
Published: August 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to use-after-free in ump_to_endpoint() when handling a subsequent open of the exposed UMP device node after a malicious USB MIDI 2.0 device causes creation to fail. An attacker with physical access can connect a malicious USB MIDI 2.0 device to trigger the dangling pointer dereference and disclose sensitive information.
The issue occurs because the UMP endpoint remains registered and its device node stays exposed after the associated snd_usb_midi2_ump object has been freed.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74501
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37
- https://git.kernel.org/stable/c/4a05b2d1b4642df74f30b6f54843e825c4a2bfd3
- https://git.kernel.org/stable/c/8a7a33b846d6ba695891b8d0040027cdbad8cd52
- https://git.kernel.org/stable/c/ae388c0e1bf727972096f770f82d12e4f748d1b6
- https://git.kernel.org/stable/c/cc014ebf803174f0e5d15956dfc5a38413c945ae