CVE-2026-74328

Source
https://cve.org/CVERecord?id=CVE-2026-74328
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74328.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74328
Downstream
Published
2026-08-15T05:58:22.371Z
Modified
2026-08-16T03:48:34.882046633Z
Summary
iommufd: Destroy the pages content after detaching from dmabuf
Details

In the Linux kernel, the following vulnerability has been resolved:

iommufd: Destroy the pages content after detaching from dmabuf

Sashiko points out this has gotten out of order, the mutex could still be in use through the dmabuf invalidation callbacks. Don't destroy any of the pages content until the dmabuf is fully detached.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74328.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
71db84a092c399f434976d0522e848e9803cd51a
Fixed
0507fcedbdcc87281ef8639c045fc9980363bbb6
Fixed
f2d70dbd3dcefa8e3c380beff9c31f5f033a4221

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74328.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74328.json"