Answer in brief
CVE-2026-74574 records a High severity (CVSS 7.8) vulnerability in dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <778ccbded2c8749c5be7f0dfa04fc9977a36fb7e || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <8d5d28285728be47c82fdf1c48be4268293c90e7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <0679c0c189d2548f00e1bac95be28e2df5c6c7f7 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <6e26a41c4c1a706edaaa7c7dffc6b3b945707a55 || >=e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec <ee1d7274102285d78a53161fc705a8d8cd40b066 | 778ccbded2c8749c5be7f0dfa04fc9977a36fb7e, 8d5d28285728be47c82fdf1c48be4268293c90e7, 0679c0c189d2548f00e1bac95be28e2df5c6c7f7, 6e26a41c4c1a706edaaa7c7dffc6b3b945707a55, ee1d7274102285d78a53161fc705a8d8cd40b066 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() The failed_dev_add and failed_dev_name paths drop the file-device reference while wq->wq_lock is still held. If put_device(fdev) drops the last reference, idxd_file_dev_release() runs synchronously and tries to take wq->wq_lock again, deadlocking. Those paths also fall through into the later ctx cleanup labels even though idxd_file_dev_release() owns that cleanup and frees ctx. This can make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context. Move idxd_wq_get() before file-device setup can fail, since the release callback always calls idxd_wq_put(). Then unlock wq->wq_lock before put_device(fdev) and return directly from the file-device setup failure path, leaving ctx cleanup to the release callback.
Quoted source text, attributed separately from HOL analysis.