CVE-2026-74418
In the Linux kernel, the following vulnerability has been resolved:
dma-fence: Fix potential tracepoint null pointer dereferences
Trace_dma_fence_signaled, trace_dma_fence_wait_end and trace_dma_fence_destroy can all currently dereference a null fence->ops pointer after it has been reset on fence signalling.
Lets use the safe string getters for most tracepoints to avoid this class of a problem, while for the signal tracepoint we move it to before ops are cleared to avoid losing the driver and timeline name information. Apart from moving it we also need to add a new tracepoint class to bypass the safe name getters since the signaled bit is already set.
Leer descripción completaMostrar menos
For dma_fence_init we also need to use the new tracepoint class since the rcu read lock is not held there, and we can do the same for the enable signaling since there we are certain the fence cannot be signaled while we are holding the lock and have even validated the fence->ops.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74418",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "541c8f2468b933acc5d129e84bd264923675a66e",
"lessThan": "4e01fc9a5bc49b04fad403ffa71299b35e132ca8",
"versionType": "git"
},
{
"status": "affected",
"version": "541c8f2468b933acc5d129e84bd264923675a66e",
"lessThan": "e94b9f01543cc6a83538c2c2cc645a424d3015ca",
"versionType": "git"
}
],
"programFiles": [
"drivers/dma-buf/dma-fence.c",
"include/trace/events/dma_fence.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/dma-buf/dma-fence.c",
"include/trace/events/dma_fence.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:43.907",
"references": [
{
"url": "https://git.kernel.org/stable/c/4e01fc9a5bc49b04fad403ffa71299b35e132ca8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e94b9f01543cc6a83538c2c2cc645a424d3015ca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-fence: Fix potential tracepoint null pointer dereferences\n\nTrace_dma_fence_signaled, trace_dma_fence_wait_end and\ntrace_dma_fence_destroy can all currently dereference a null fence->ops\npointer after it has been reset on fence signalling.\n\nLets use the safe string getters for most tracepoints to avoid this class\nof a problem, while for the signal tracepoint we move it to before ops are\ncleared to avoid losing the driver and timeline name information. Apart\nfrom moving it we also need to add a new tracepoint class to bypass the\nsafe name getters since the signaled bit is already set.\n\nFor dma_fence_init we also need to use the new tracepoint class since the\nrcu read lock is not held there, and we can do the same for the enable\nsignaling since there we are certain the fence cannot be signaled while\nwe are holding the lock and have even validated the fence->ops."
}
],
"lastModified": "2026-08-17T06:19:37.283",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}