PT-2026-72892 · Linux · Linux Kernel

CVE-2026-74440

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the xe exec ioctl() function where the system failed to wait on the DMA RESV USAGE KERNEL slots of external Buffer Objects (BOs). The DMA RESV USAGE KERNEL slot is a cross-driver contract ensuring memory management operations, such as evictions or moves, complete before the BO is accessed. By only adding the VM's dma-resv KERNEL slot as a dependency, the execution path could schedule a user job while a kernel operation on an external BO was still active. This creates a race condition that may lead to reading or writing memory while it is being moved.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-74440

Affected Products

Linux Kernel