CVE-2026-74328

Summary

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Destroy the pages content after detaching from dmabuf

Sashiko points out this has gotten out of order, the mutex could still be in use through the dmabuf invalidation callbacks. Don't destroy any of the pages content until the dmabuf is fully detached.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux71db84a092c399f434976d0522e848e9803cd51a < 0507fcedbdcc87281ef8639c045fc9980363bbb6affected
LinuxLinux71db84a092c399f434976d0522e848e9803cd51a < f2d70dbd3dcefa8e3c380beff9c31f5f033a4221affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References