CVE-2026-74629
Last modified
CVE-2026-74629 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A dibs device interrupt handler can be active after dibs_dev_del() and may still access dmb_clientid_arr. (UAF) In case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe() dmb_clientid_arr is freed twice (double free). Free dmb_clientid_arr in dibs_dev_release() after last reference is gone. Note that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok for now, because no dmbs can be registered before dibs_dev_add()..
Description
In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A dibs device interrupt handler can be active after dibs_dev_del() and may still access dmb_clientid_arr. (UAF) In case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe() dmb_clientid_arr is freed twice (double free). Free dmb_clientid_arr in dibs_dev_release() after last reference is gone. Note that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok for now, because no dmbs can be registered before dibs_dev_add().
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cc21191b584c6f7836b0f10774f8278b7cbfba10, < ece6426b61241e9bfb41aa131f235168f55229b1; >= cc21191b584c6f7836b0f10774f8278b7cbfba10, < 7a1df20a8d2cc89e3a442b6e0b43b1cacde8d403; >= cc21191b584c6f7836b0f10774f8278b7cbfba10, < 9e6869be49064915edb6c8776b27c376cfdb0df5 |
| Linux | Linux | 6.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74629?
How severe is CVE-2026-74629?
How do I fix CVE-2026-74629?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74623In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74624In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74625In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74626In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74627In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74628In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74630In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74631In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74632In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74633In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74634In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74635In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74629?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
