CVE-2026-74642
Last modified
CVE-2026-74642 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: usb: Fix UAF at delayed release of MIDI2 EPs The recent fix for UAF in ump_to_endpoint() caused another UAF because it tries to dereference the UMP endpoint object, but this might be executed at a delayed context where the endpoint has been already released. Add private_free to clear the associated data for avoiding the further dereference for delayed releases..
Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb: Fix UAF at delayed release of MIDI2 EPs The recent fix for UAF in ump_to_endpoint() caused another UAF because it tries to dereference the UMP endpoint object, but this might be executed at a delayed context where the endpoint has been already released. Add private_free to clear the associated data for avoiding the further dereference for delayed releases.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37, < d431941825d357be7d9ab0cb7505e3a1963bd89e; >= 8a7a33b846d6ba695891b8d0040027cdbad8cd52, < 422d8a02de5ce6a29d616d55e5ead5dec69ac1d7; >= cc014ebf803174f0e5d15956dfc5a38413c945ae, < d217d723c5e43881b952cdb978477f7f2dc0b6d7; >= ae388c0e1bf727972096f770f82d12e4f748d1b6, < f9d492a39ebeb1a56f13ec6dd165a18a48dec812; >= 4a05b2d1b4642df74f30b6f54843e825c4a2bfd3, < f8a80cfb68613fb7e6452b66447dbc63f435d140 |
| Linux | Linux | >= 6.6.151, < 6.6.152; >= 6.12.103, < 6.12.104; >= 6.18.44, < 6.18.45; >= 7.1.8, < 7.1.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74642?
How severe is CVE-2026-74642?
How do I fix CVE-2026-74642?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74637In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74638In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74639In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7464The WP Google Maps Integration plugin for WordPress is vulne…6.1
- CVE-2026-74640In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74641In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74643In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74644In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74645In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74646In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74647In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74648In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74642?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
