PT-2026-72933 · Linux · Linux Kernel

CVE-2026-74481

·

Published

2026-08-15

·

Updated

2026-08-18

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A Use-After-Free (UAF) and General Protection Fault can occur during Power Management (PM) freeze, such as S3 suspend or S4 hibernation. The issue arises because the page reporting process is scheduled on the global system wq, which lacks the WQ FREEZABLE flag. Consequently, the PM freezer does not pause this process during suspend. If pages are freed into the buddy allocator while suspending, the system may trigger the virtballoon free page report() function on virtqueues that have already been deleted via vdev->config->del vqs(), leading to a crash. The vulnerability involves the page reporting process function and the virtballoon free page report() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-96102
CVE-2026-74481

Affected Products

Linux Kernel