NULL pointer dereference in Linux kernel - CVE-2026-74732

 

NULL pointer dereference in Linux kernel - CVE-2026-74732

Published: August 24, 2026


Vulnerability identifier: #VU144600
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74732
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to a NULL pointer dereference in dce110_set_avmute in the AMD display driver when turning the display off over HDMI. A local user can trigger the vulnerable code path to cause a denial of service.

The issue affects Southern Islands discrete GPUs and is reached while waiting for AV mute frames.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74732

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins