Answer in brief
CVE-2026-74421 records a Unknown severity vulnerability in drm/rockchip: dw_dp: Switch to drmm_kzalloc(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <0d60b835bca42f0f790689dd47819ed881a92ccc || >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12 || >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <ed9da8d23020352ad24c528db09b5acdd78b81fd | 0d60b835bca42f0f790689dd47819ed881a92ccc, 6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12, ed9da8d23020352ad24c528db09b5acdd78b81fd |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Switch to drmm_kzalloc() Driver makes use of drmm_encoder_init() to initialize the encoder and automatically handle the cleanup by registering drm_encoder_cleanup() with drmm_add_action(). However, the internal structure containing the encoder part gets allocated with devm_kzalloc(), which happens while component_bind_all() is being called from Rockchip DRM driver. The component framework further ensures it is deallocated as part of releasing all the resources claimed during bind, which is triggered from component_unbind_all(). When the reference to the DRM device gets eventually dropped via drm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release() attempts to access the now released encoder structure, leading to use-after-free. Ensure driver's internal structure is still reachable on encoder cleanup by switching from a device-managed allocation to a drm-managed one.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74421 records a Unknown severity vulnerability in drm/rockchip: dw_dp: Switch to drmm_kzalloc(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <0d60b835bca42f0f790689dd47819ed881a92ccc || >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12 || >=d68ba7bac9555d05e2f5b310c898b2a5c7eff174 <ed9da8d23020352ad24c528db09b5acdd78b81fd | 0d60b835bca42f0f790689dd47819ed881a92ccc, 6b0b92d1110eccccbd5ba2949bd2b9fb6ea5fc12, ed9da8d23020352ad24c528db09b5acdd78b81fd |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: dw_dp: Switch to drmm_kzalloc() Driver makes use of drmm_encoder_init() to initialize the encoder and automatically handle the cleanup by registering drm_encoder_cleanup() with drmm_add_action(). However, the internal structure containing the encoder part gets allocated with devm_kzalloc(), which happens while component_bind_all() is being called from Rockchip DRM driver. The component framework further ensures it is deallocated as part of releasing all the resources claimed during bind, which is triggered from component_unbind_all(). When the reference to the DRM device gets eventually dropped via drm_dev_put() in rockchip_drm_unbind(), drmm_encoder_alloc_release() attempts to access the now released encoder structure, leading to use-after-free. Ensure driver's internal structure is still reachable on encoder cleanup by switching from a device-managed allocation to a drm-managed one.
Quoted source text, attributed separately from HOL analysis.