CVE-2026-74416
In the Linux kernel, the following vulnerability has been resolved:
drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
radeon_ring_restore() takes ownership of the data buffer allocated by radeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in the non-restore branch; in the restore branch it relies on radeon_ring_restore() to free it.
If radeon_ring_lock() fails, the function returned early without calling kvfree(data), leaking the ring backup buffer on every GPU reset that fails at the lock stage. During repeated GPU resets this causes cumulative kernel memory exhaustion.
Leer descripción completaMostrar menos
Free data before returning the error.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/06dc892561f5a08b2493c34c8ec2cb94dea33159
- https://git.kernel.org/stable/c/07c213f3499dd72e2922c1c73fe9ffea24874bef
- https://git.kernel.org/stable/c/1c9ba32308c02c198c378fcdf06be9ffc3111147
- https://git.kernel.org/stable/c/63912418f1fbb6456ea04bbcdf8f4d5090d23350
- https://git.kernel.org/stable/c/82f1d6042611d45b8b9de423bbcb4e0ced9ec62b
- https://git.kernel.org/stable/c/919e3e398bf301c6418dffdcd5e5c4fd9be39cf7
- https://git.kernel.org/stable/c/ccc42187fc2d0720947a63ce1b9e399d2c068ff4
- https://git.kernel.org/stable/c/eecfb76129ebef7e3aa41e18a4668cd91dfc6267
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74416",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "63912418f1fbb6456ea04bbcdf8f4d5090d23350",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "919e3e398bf301c6418dffdcd5e5c4fd9be39cf7",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "07c213f3499dd72e2922c1c73fe9ffea24874bef",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "1c9ba32308c02c198c378fcdf06be9ffc3111147",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "eecfb76129ebef7e3aa41e18a4668cd91dfc6267",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "06dc892561f5a08b2493c34c8ec2cb94dea33159",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "ccc42187fc2d0720947a63ce1b9e399d2c068ff4",
"versionType": "git"
},
{
"status": "affected",
"version": "55d7c22192becd0ec827a6901899ff56fa985658",
"lessThan": "82f1d6042611d45b8b9de423bbcb4e0ced9ec62b",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/radeon/radeon_ring.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.6"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.6",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/radeon/radeon_ring.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:22:43.690",
"references": [
{
"url": "https://git.kernel.org/stable/c/06dc892561f5a08b2493c34c8ec2cb94dea33159",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/07c213f3499dd72e2922c1c73fe9ffea24874bef",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1c9ba32308c02c198c378fcdf06be9ffc3111147",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/63912418f1fbb6456ea04bbcdf8f4d5090d23350",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/82f1d6042611d45b8b9de423bbcb4e0ced9ec62b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/919e3e398bf301c6418dffdcd5e5c4fd9be39cf7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ccc42187fc2d0720947a63ce1b9e399d2c068ff4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/eecfb76129ebef7e3aa41e18a4668cd91dfc6267",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix memory leak in radeon_ring_restore() on lock failure\n\nradeon_ring_restore() takes ownership of the data buffer allocated by\nradeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in\nthe non-restore branch; in the restore branch it relies on\nradeon_ring_restore() to free it.\n\nIf radeon_ring_lock() fails, the function returned early without calling\nkvfree(data), leaking the ring backup buffer on every GPU reset that\nfails at the lock stage. During repeated GPU resets this causes\ncumulative kernel memory exhaustion.\n\nFree data before returning the error."
}
],
"lastModified": "2026-08-17T06:19:37.063",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}