CVE-2026-74687

Unknown

Last modified

CVE-2026-74687 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed. Use timer_shutdown_sync() on both teardown paths.

Description

In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed. Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 5161b31dc39a6d6dadc95f298de48a725b73ada8, < 29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed; >= 5161b31dc39a6d6dadc95f298de48a725b73ada8, < b7949b0a7d998013b7ec8617a0ef5b07cca80be4; >= 5161b31dc39a6d6dadc95f298de48a725b73ada8, < 8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783
LinuxLinux3.14

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74687?
In the Linux kernel, the following vulnerability has been resolved: watchdog: at91sam9_wdt: prevent timer rearm during teardown at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed. Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.
How severe is CVE-2026-74687?
Severity scoring for CVE-2026-74687 is pending analysis.
How do I fix CVE-2026-74687?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74687?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST