CVE-2026-74505

UnknownEPSS 0.17%

Last modified

CVE-2026-74505 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.

Metrics

EPSS Probability
0.17%

6.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < d41bfea14ee6e063a953f6e72046088737c4e66c; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < 8b7ecb2446845fa8d1f1ce9aac6307caac50cfd5; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < a0bb5b9d39e54888385dc399c899223299201fe6; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < 49bc7741cd2761c703a292dc69245041ae8a67bd; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < 2de734dcbb210bd59983e13d36988acbcc122194; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < 11e2953d9f4c7c3d2af94a889c2d805c537d633f; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < 630c8d6a93cbd9b2a207f1a67ef1fd21af098b0c; >= c6d43ba816d1cf1d125bfbfc938f2a28a87facf9, < a54bf16965f896415c3337bc4fbb40fb11941d99
LinuxLinux2.6.39

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74505?
In the Linux kernel, the following vulnerability has been resolved: ALSA: 6fire: Fix UAF at error handling during probe Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF. This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.
How severe is CVE-2026-74505?
Severity scoring for CVE-2026-74505 is pending analysis. The EPSS model estimates a 0.17% probability of exploitation in the next 30 days.
How do I fix CVE-2026-74505?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74505?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST