Use-after-free in Linux kernel - CVE-2026-74450

 

Use-after-free in Linux kernel - CVE-2026-74450

Published: August 16, 2026


Vulnerability identifier: #VU143333
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74450
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in the amdgpu pp_table sysfs handling when copying the power table after dropping adev->pm.mutex. A local user can trigger a concurrent pp_table write during the copy to cause a denial of service.

The issue arises because a driver-owned power table pointer is returned and later used by the sysfs path after the mutex is released.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74450

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins