Linux Kernel Vulnerability in DMA Engine Affecting Multiple Versions
CVE-2026-74574
What is CVE-2026-74574?
In the Linux kernel, a vulnerability exists within the DMA engine that can lead to a deadlock condition during the device setup process in idxd_cdev_open(). This is caused by the mishandling of file-device references when the device setup fails, which drops references while holding essential locks. As a result, conflicts may occur during cleanup operations, leading to potential resource leaks and instability. The issue has been addressed by restructuring the order of operations to ensure proper lock management and reference handling.
Affected Version(s)
Linux e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec < 778ccbded2c8749c5be7f0dfa04fc9977a36fb7e
Linux e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec < 8d5d28285728be47c82fdf1c48be4268293c90e7
Linux e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec < 0679c0c189d2548f00e1bac95be28e2df5c6c7f7