Null Pointer Dereference Vulnerability in Linux Kernel Affecting DMA Fencing Operations
CVE-2026-74418

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74418?

A vulnerability exists in the Linux kernel related to the handling of dma-fence operations, potentially leading to null pointer dereference. Specifically, the issues lie within the tracepoints for dma-fence signaling, where a null fence->ops pointer may be dereferenced after being reset. This could allow attackers to manipulate kernel operations improperly. The fix involves utilizing safe string getters for various tracepoints, and judiciously repositioning tracepoints to maintain essential driver and timeline name information while avoiding null pointer dereferences.

Affected Version(s)

Linux 541c8f2468b933acc5d129e84bd264923675a66e < 4e01fc9a5bc49b04fad403ffa71299b35e132ca8

Linux 541c8f2468b933acc5d129e84bd264923675a66e

Linux 7.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.