« Volver al listado

CVE-2026-74574

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()

The failed_dev_add and failed_dev_name paths drop the file-device reference while wq->wq_lock is still held. If put_device(fdev) drops the last reference, idxd_file_dev_release() runs synchronously and tries to take wq->wq_lock again, deadlocking.

Those paths also fall through into the later ctx cleanup labels even though idxd_file_dev_release() owns that cleanup and frees ctx. This can make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context.

Move idxd_wq_get() before file-device setup can fail, since the release callback always calls idxd_wq_put().

Leer descripción completaMostrar menos

Then unlock wq->wq_lock before put_device(fdev) and return directly from the file-device setup failure path, leaving ctx cleanup to the release callback.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L, PR:L, sin UI: escalada de privilegios local. Deadlock y use-after-free en kernel permiten DoS y corrupción de memoria desde contexto sin privilegios.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74574",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec",
              "lessThan": "778ccbded2c8749c5be7f0dfa04fc9977a36fb7e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec",
              "lessThan": "8d5d28285728be47c82fdf1c48be4268293c90e7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec",
              "lessThan": "0679c0c189d2548f00e1bac95be28e2df5c6c7f7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec",
              "lessThan": "6e26a41c4c1a706edaaa7c7dffc6b3b945707a55",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec",
              "lessThan": "ee1d7274102285d78a53161fc705a8d8cd40b066",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/dma/idxd/cdev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/dma/idxd/cdev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:18:03.063",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0679c0c189d2548f00e1bac95be28e2df5c6c7f7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e26a41c4c1a706edaaa7c7dffc6b3b945707a55",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/778ccbded2c8749c5be7f0dfa04fc9977a36fb7e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8d5d28285728be47c82fdf1c48be4268293c90e7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee1d7274102285d78a53161fc705a8d8cd40b066",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()\n\nThe failed_dev_add and failed_dev_name paths drop the file-device\nreference while wq->wq_lock is still held. If put_device(fdev) drops the\nlast reference, idxd_file_dev_release() runs synchronously and tries to\ntake wq->wq_lock again, deadlocking.\n\nThose paths also fall through into the later ctx cleanup labels even\nthough idxd_file_dev_release() owns that cleanup and frees ctx. This can\nmake idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context.\n\nMove idxd_wq_get() before file-device setup can fail, since the release\ncallback always calls idxd_wq_put(). Then unlock wq->wq_lock before\nput_device(fdev) and return directly from the file-device setup failure\npath, leaving ctx cleanup to the release callback."
    }
  ],
  "lastModified": "2026-08-17T06:19:55.750",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}