Race condition in Linux kernel - CVE-2026-74647
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in fastrpc_req_munmap_impl in the fastrpc driver when processing concurrent buffer unmap requests. A local user can trigger concurrent unmap operations to cause a denial of service.
The issue occurs when multiple threads invoke unmap concurrently for the same buffer.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74647
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5
- https://git.kernel.org/stable/c/6102ceb4eab845743ee57acd3863fbd06e93c927
- https://git.kernel.org/stable/c/97273624f7b356eaf8261609a75cfcb8738a165a
- https://git.kernel.org/stable/c/9bf22a7d950cec2d1efeca7f16bb20fcca84c36a
- https://git.kernel.org/stable/c/fe70329055977fc1e8dc6291318d0dd75470795a