Use-after-free in Linux kernel - CVE-2026-74608
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in cifs_try_adding_channels() when handling channel addition failures during concurrent interface list refresh. A local user can trigger the race condition to cause a denial of service.
The issue occurs on the failure path after channel creation fails and concurrent interface list refresh removes the remaining list reference.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74608
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1305eadc6a7d78a8d0a52eee29ddd2d9e8a27805
- https://git.kernel.org/stable/c/1ffacbadc14530e55b8d86f7b917524f6a0fb891
- https://git.kernel.org/stable/c/47dfac48bce7198ad4f1a388fc8c9491f878ac3b
- https://git.kernel.org/stable/c/4986410316b1ae0e63c6ce418e4eb196723626e7
- https://git.kernel.org/stable/c/64d7584e62ac8cdc750455c5fdc6008fc2de4f06
- https://git.kernel.org/stable/c/c292d4686f717c03e5022fc4ae7c782f39a94915