Linux Kernel idxd DMAengine Deadlock/UAF CVE-2026-74574
CVE-2026-74574 Published on August 15, 2026
dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open()
The failed_dev_add and failed_dev_name paths drop the file-device
reference while wq->wq_lock is still held. If put_device(fdev) drops the
last reference, idxd_file_dev_release() runs synchronously and tries to
take wq->wq_lock again, deadlocking.
Those paths also fall through into the later ctx cleanup labels even
though idxd_file_dev_release() owns that cleanup and frees ctx. This can
make idxd_xa_pasid_remove(ctx) and kfree(ctx) operate on a freed context.
Move idxd_wq_get() before file-device setup can fail, since the release
callback always calls idxd_wq_put(). Then unlock wq->wq_lock before
put_device(fdev) and return directly from the file-device setup failure
path, leaving ctx cleanup to the release callback.
Products Associated with CVE-2026-74574
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec and below 778ccbded2c8749c5be7f0dfa04fc9977a36fb7e is affected.
- Version e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec and below 8d5d28285728be47c82fdf1c48be4268293c90e7 is affected.
- Version e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec and below 0679c0c189d2548f00e1bac95be28e2df5c6c7f7 is affected.
- Version e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec and below 6e26a41c4c1a706edaaa7c7dffc6b3b945707a55 is affected.
- Version e6fd6d7e5f0fe4a17a08e892afb5db800e7794ec and below ee1d7274102285d78a53161fc705a8d8cd40b066 is affected.
- Version 6.4 is affected.
- Before 6.4 is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.