« Volver al listado

CVE-2026-74647

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

misc: fastrpc: Remove buffer from list prior to unmap operation

fastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is getting removed from the list after it is unmapped from DSP. This can create potential race conditions if multiple threads invoke unmap concurrently, where one thread may remove the entry from the list while another thread's unmap operation is still ongoing.

Fix this by removing the buffer entry from the list before calling the unmap operation.

Leer descripción completaMostrar menos

If the unmap fails, the entry is re-added to the list so that userspace can retry the unmap, or alternatively, the buffer will be cleaned up during device release when the DSP process is torn down and all DSP-side mappings are freed along with remaining buffers in the list.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L/PR:L sin UI permite escalada local mediante race condition en desmapeo. Impactos: DoS por crash concurrente y corrupción de memoria compartida DSP-usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74647",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "1edb654b2b41baee2ab5cf418baaf6e57dfbd802",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "4716c23c206a2f99ca54ebfdd8b5ba9dd0102240",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "99f8de36c84cb9b872157aa6c3578c2480cee4b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "97273624f7b356eaf8261609a75cfcb8738a165a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "fe70329055977fc1e8dc6291318d0dd75470795a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "9bf22a7d950cec2d1efeca7f16bb20fcca84c36a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2419e55e532de14fdf336e09e453aa2831c73a25",
              "lessThan": "6102ceb4eab845743ee57acd3863fbd06e93c927",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/misc/fastrpc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.267",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.218",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.185",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/misc/fastrpc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:38.050",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0beaa9bd7eb10d9b5e6352ed5161f3f3bbd4c3c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1edb654b2b41baee2ab5cf418baaf6e57dfbd802",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4716c23c206a2f99ca54ebfdd8b5ba9dd0102240",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6102ceb4eab845743ee57acd3863fbd06e93c927",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/97273624f7b356eaf8261609a75cfcb8738a165a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/99f8de36c84cb9b872157aa6c3578c2480cee4b8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9bf22a7d950cec2d1efeca7f16bb20fcca84c36a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fe70329055977fc1e8dc6291318d0dd75470795a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Remove buffer from list prior to unmap operation\n\nfastrpc_req_munmap_impl() is called to unmap any buffer. The buffer is\ngetting removed from the list after it is unmapped from DSP. This can\ncreate potential race conditions if multiple threads invoke unmap\nconcurrently, where one thread may remove the entry from the list while\nanother thread's unmap operation is still ongoing.\n\nFix this by removing the buffer entry from the list before calling the\nunmap operation. If the unmap fails, the entry is re-added to the list\nso that userspace can retry the unmap, or alternatively, the buffer\nwill be cleaned up during device release when the DSP process is torn\ndown and all DSP-side mappings are freed along with remaining buffers\nin the list."
    }
  ],
  "lastModified": "2026-08-27T13:18:35.540",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}