Answer in brief
CVE-2026-74519 records a Unknown severity vulnerability in pinctrl: devicetree: don't free uninitialized dev_name on error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=be4c60b563edee3712d392aaeb0943a768df7023 <929f6396baade89999ec8a1281232c101cbc727d || >=be4c60b563edee3712d392aaeb0943a768df7023 <321fe3584a8298386938130d138191aa35040b75 || >=be4c60b563edee3712d392aaeb0943a768df7023 <ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8 || >=be4c60b563edee3712d392aaeb0943a768df7023 <9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d || >=be4c60b563edee3712d392aaeb0943a768df7023 <015b5bcbcb622b32317642be91a7f79aa5413649 || 03f69244302d7954f42f528ea2d45903ebbf59f3 || 77440c3a37203e3f4667d06e37f76ef3968d2d8c || 679c4f27b8958b65bb51d1c3dfdbf3befe4a33a3 || f88ac1330779c5bfdd79f7d7f7d4d3343c782f92 || f739a699db7d5a5cf39ca3ce2c84e4fe4a8f4c5d || >=4.4.244 <4.5 || >=4.9.244 <4.10 || >=4.14.161 <4.15 || >=4.19.92 <4.20 || >=5.4.7 <5.5 | 929f6396baade89999ec8a1281232c101cbc727d, 321fe3584a8298386938130d138191aa35040b75, ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8, 9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d, 015b5bcbcb622b32317642be91a7f79aa5413649, 4.5, 4.10, 4.15, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_name on error path dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps entries, including entries that have not been initialized. Some pinctrl drivers, including pinctrl-imx, allocate the map with kmalloc() and leave dev_name for the core to initialize. The untouched entries therefore contain uninitialized data which is passed to kfree_const(). Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection while binding the pinctrl-consuming device, under KASAN: BUG: KASAN: double-free in dt_free_map+0x34/0xa4 Free of addr c425a900 by task init/1 kfree from dt_free_map+0x34/0xa4 dt_free_map from dt_remember_or_free_map+0x184/0x198 dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8 pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0 Initialize all dev_name fields to NULL before duplicating the device name, making the full-map cleanup safe after a partial failure.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74519 records a Unknown severity vulnerability in pinctrl: devicetree: don't free uninitialized dev_name on error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=be4c60b563edee3712d392aaeb0943a768df7023 <929f6396baade89999ec8a1281232c101cbc727d || >=be4c60b563edee3712d392aaeb0943a768df7023 <321fe3584a8298386938130d138191aa35040b75 || >=be4c60b563edee3712d392aaeb0943a768df7023 <ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8 || >=be4c60b563edee3712d392aaeb0943a768df7023 <9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d || >=be4c60b563edee3712d392aaeb0943a768df7023 <015b5bcbcb622b32317642be91a7f79aa5413649 || 03f69244302d7954f42f528ea2d45903ebbf59f3 || 77440c3a37203e3f4667d06e37f76ef3968d2d8c || 679c4f27b8958b65bb51d1c3dfdbf3befe4a33a3 || f88ac1330779c5bfdd79f7d7f7d4d3343c782f92 || f739a699db7d5a5cf39ca3ce2c84e4fe4a8f4c5d || >=4.4.244 <4.5 || >=4.9.244 <4.10 || >=4.14.161 <4.15 || >=4.19.92 <4.20 || >=5.4.7 <5.5 | 929f6396baade89999ec8a1281232c101cbc727d, 321fe3584a8298386938130d138191aa35040b75, ad0ad3c228b6f76fde10f32047e0ec5fbc109dc8, 9d00a5ac7cd3d32ae61140f4b8a62f136de84e7d, 015b5bcbcb622b32317642be91a7f79aa5413649, 4.5, 4.10, 4.15, 4.20, 5.5 |
| Linux/Linuxgeneric | 5.5 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_name on error path dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps entries, including entries that have not been initialized. Some pinctrl drivers, including pinctrl-imx, allocate the map with kmalloc() and leave dev_name for the core to initialize. The untouched entries therefore contain uninitialized data which is passed to kfree_const(). Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection while binding the pinctrl-consuming device, under KASAN: BUG: KASAN: double-free in dt_free_map+0x34/0xa4 Free of addr c425a900 by task init/1 kfree from dt_free_map+0x34/0xa4 dt_free_map from dt_remember_or_free_map+0x184/0x198 dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8 pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0 Initialize all dev_name fields to NULL before duplicating the device name, making the full-map cleanup safe after a partial failure.
Quoted source text, attributed separately from HOL analysis.