Answer in brief
CVE-2026-74574 records a Unknown severity vulnerability in dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <778ccbded2c8749c5be7f0dfa04fc9977a36fb7e || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <8d5d28285728be47c82fdf1c48be4268293c90e7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <0679c0c189d2548f00e1bac95be28e2df5c6c7f7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <6e26a41c4c1a706edaaa7c7dffc6b3b945707a55 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <ee1d7274102285d78a53161fc705a8d8cd40b066 | 778ccbded2c8749c5be7f0dfa04fc9977a36fb7e, 8d5d28285728be47c82fdf1c48be4268293c90e7, 0679c0c189d2548f00e1bac95be28e2df5c6c7f7, 6e26a41c4c1a706edaaa7c7dffc6b3b945707a55, ee1d7274102285d78a53161fc705a8d8cd40b066 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() The failed_dev_add and failed_dev_name paths drop the file-device reference while wq->wq_lock is still held. If put_device(fdev) drops the last reference, idxd_file_dev_release() runs synchronously and tries to take wq->wq_lock again, deadlocking. Those paths also fall through into the later ctx cleanup labels even though idxd_file_dev_release() owns that cleanup and frees ctx. This can make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context. Move idxd_wq_get() before file-device setup can fail, since the release callback always calls idxd_wq_put(). Then unlock wq->wq_lock before put_device(fdev) and return directly from the file-device setup failure path, leaving ctx cleanup to the release callback.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74574 records a Unknown severity vulnerability in dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <778ccbded2c8749c5be7f0dfa04fc9977a36fb7e || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <8d5d28285728be47c82fdf1c48be4268293c90e7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <0679c0c189d2548f00e1bac95be28e2df5c6c7f7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <6e26a41c4c1a706edaaa7c7dffc6b3b945707a55 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <ee1d7274102285d78a53161fc705a8d8cd40b066 | 778ccbded2c8749c5be7f0dfa04fc9977a36fb7e, 8d5d28285728be47c82fdf1c48be4268293c90e7, 0679c0c189d2548f00e1bac95be28e2df5c6c7f7, 6e26a41c4c1a706edaaa7c7dffc6b3b945707a55, ee1d7274102285d78a53161fc705a8d8cd40b066 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() The failed_dev_add and failed_dev_name paths drop the file-device reference while wq->wq_lock is still held. If put_device(fdev) drops the last reference, idxd_file_dev_release() runs synchronously and tries to take wq->wq_lock again, deadlocking. Those paths also fall through into the later ctx cleanup labels even though idxd_file_dev_release() owns that cleanup and frees ctx. This can make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context. Move idxd_wq_get() before file-device setup can fail, since the release callback always calls idxd_wq_put(). Then unlock wq->wq_lock before put_device(fdev) and return directly from the file-device setup failure path, leaving ctx cleanup to the release callback.
Quoted source text, attributed separately from HOL analysis.