Use-after-free in Linux kernel - CVE-2026-74481

 

Use-after-free in Linux kernel - CVE-2026-74481

Published: August 16, 2026


Vulnerability identifier: #VU143308
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74481
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a use-after-free in page_reporting_process and virtballoon_free_page_report when page reporting work continues during power management freeze while virtqueues are being deleted. A local user can trigger suspend or hibernation activity while freed pages are being reported to access deleted virtqueues and cause a denial of service.

The issue can be reached during S3 suspend or S4 hibernation, including cases where memory reclamation returns pages to the buddy allocator during image saving.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74481

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins