Use-after-free in Linux kernel - CVE-2026-74639

 

Use-after-free in Linux kernel - CVE-2026-74639

Published: August 24, 2026


Vulnerability identifier: #VU144892
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74639
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code or cause a denial of service.

The vulnerability exists due to a use-after-free in capture_urb_complete() and the capture URB anchoring logic when resubmitting capture URBs from their completion handler. A local user can trigger capture URB resubmission and subsequent device disconnect, suspend, or stop-work handling to execute arbitrary code or cause a denial of service.

The issue occurs because resubmitted URBs are no longer tracked by the anchor, allowing queued URBs to complete after the transfer buffers and driver object have been freed.


Affected software

Linux kernel

How to mitigate CVE-2026-74639

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins