CVE-2026-74687
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
watchdog: at91sam9_wdt: prevent timer rearm during teardown
at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed.
Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5161b31dc39a6d6dadc95f298de48a725b73ada8 < 29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed | affected |
| Linux | Linux | 5161b31dc39a6d6dadc95f298de48a725b73ada8 < b7949b0a7d998013b7ec8617a0ef5b07cca80be4 | affected |
| Linux | Linux | 5161b31dc39a6d6dadc95f298de48a725b73ada8 < 8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783 | affected |
| Linux | Linux | 3.14 | affected |
| Linux | Linux | 0 < 3.14 | unaffected |
| Linux | Linux | 6.18.45 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.9 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed
- https://git.kernel.org/stable/c/b7949b0a7d998013b7ec8617a0ef5b07cca80be4
- https://git.kernel.org/stable/c/8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.