Answer in brief
CVE-2026-74629 records a Unknown severity vulnerability in net/dibs: Correct freeing of dmb_clientid_arr. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cc21191b584c6f7836b0f10774f8278b7cbfba10 <ece6426b61241e9bfb41aa131f235168f55229b1 || >=cc21191b584c6f7836b0f10774f8278b7cbfba10 <7a1df20a8d2cc89e3a442b6e0b43b1cacde8d403 || >=cc21191b584c6f7836b0f10774f8278b7cbfba10 <9e6869be49064915edb6c8776b27c376cfdb0df5 | ece6426b61241e9bfb41aa131f235168f55229b1, 7a1df20a8d2cc89e3a442b6e0b43b1cacde8d403, 9e6869be49064915edb6c8776b27c376cfdb0df5 |
| Linux/Linuxgeneric | 6.18 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: net/dibs: Correct freeing of dmb_clientid_arr A dibs device interrupt handler can be active after dibs_dev_del() and may still access dmb_clientid_arr. (UAF) In case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe() dmb_clientid_arr is freed twice (double free). Free dmb_clientid_arr in dibs_dev_release() after last reference is gone. Note that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok for now, because no dmbs can be registered before dibs_dev_add().
Quoted source text, attributed separately from HOL analysis.