CVE-2026-74687 is a vulnerability in Linux Kernel
Published on August 22, 2026
watchdog: at91sam9_wdt: prevent timer rearm during teardown
In the Linux kernel, the following vulnerability has been resolved:
watchdog: at91sam9_wdt: prevent timer rearm during teardown
at91_ping() rearms the watchdog timer from its callback. timer_delete()
neither waits for a running callback nor prevents it from rearming the
timer, so probe failure or driver removal can leave the timer accessing the
devm-allocated at91wdt after it has been freed.
Use timer_shutdown_sync() on both teardown paths. It waits for a running
callback and rejects any attempt by the callback to rearm the timer.
Products Associated with CVE-2026-74687
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 5161b31dc39a6d6dadc95f298de48a725b73ada8 and below 29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed is affected.
- Version 5161b31dc39a6d6dadc95f298de48a725b73ada8 and below b7949b0a7d998013b7ec8617a0ef5b07cca80be4 is affected.
- Version 5161b31dc39a6d6dadc95f298de48a725b73ada8 and below 8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783 is affected.
- Version 3.14 is affected.
- Before 3.14 is unaffected.
- Version 6.18.45, <= 6.18.* is unaffected.
- Version 7.1.9, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.