Answer in brief
CVE-2026-74313 records a Unknown severity vulnerability in vduse: hold vduse_lock across IDR lookup in open path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-74313 records a Unknown severity vulnerability in vduse: hold vduse_lock across IDR lookup in open path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c8a6153b6c59d95c0e091f053f6f180952ade91e <35483c5306e09b3190ff937089d404a78012695c || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <5c1560be8aa6849356455af67518d35c551cbd95 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <93ed4692f2299a40346025979f40e4a9b7b33af7 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <d94e2947203aead590fd63f667d316d4475d65af || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <79e12c891940b0c4c75881b7fd82a8cbb8ac97be || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <e440e077748939839d9f76e24383b76b785f80ce | 35483c5306e09b3190ff937089d404a78012695c, 5c1560be8aa6849356455af67518d35c551cbd95, 93ed4692f2299a40346025979f40e4a9b7b33af7, d94e2947203aead590fd63f667d316d4475d65af, a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2, 79e12c891940b0c4c75881b7fd82a8cbb8ac97be, e440e077748939839d9f76e24383b76b785f80ce |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: vduse: hold vduse_lock across IDR lookup in open path vduse_dev_open() looks up struct vduse_dev through the IDR and then acquires dev->lock only after vduse_lock has been dropped. This leaves a window where a concurrent VDUSE_DESTROY_DEV can remove the same object from the IDR and free it before the open path locks the device, leading to a use-after-free. Close this race by keeping vduse_lock held until dev->lock has been acquired in the open path, matching the lock ordering already used by the destroy path.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c8a6153b6c59d95c0e091f053f6f180952ade91e <35483c5306e09b3190ff937089d404a78012695c || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <5c1560be8aa6849356455af67518d35c551cbd95 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <93ed4692f2299a40346025979f40e4a9b7b33af7 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <d94e2947203aead590fd63f667d316d4475d65af || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2 || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <79e12c891940b0c4c75881b7fd82a8cbb8ac97be || >=c8a6153b6c59d95c0e091f053f6f180952ade91e <e440e077748939839d9f76e24383b76b785f80ce | 35483c5306e09b3190ff937089d404a78012695c, 5c1560be8aa6849356455af67518d35c551cbd95, 93ed4692f2299a40346025979f40e4a9b7b33af7, d94e2947203aead590fd63f667d316d4475d65af, a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2, 79e12c891940b0c4c75881b7fd82a8cbb8ac97be, e440e077748939839d9f76e24383b76b785f80ce |
| Linux/Linuxgeneric | 5.15 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: vduse: hold vduse_lock across IDR lookup in open path vduse_dev_open() looks up struct vduse_dev through the IDR and then acquires dev->lock only after vduse_lock has been dropped. This leaves a window where a concurrent VDUSE_DESTROY_DEV can remove the same object from the IDR and free it before the open path locks the device, leading to a use-after-free. Close this race by keeping vduse_lock held until dev->lock has been acquired in the open path, matching the lock ordering already used by the destroy path.
Quoted source text, attributed separately from HOL analysis.