CVE-2026-74477

Source
https://cve.org/CVERecord?id=CVE-2026-74477
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74477.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74477
Downstream
Published
2026-08-15T12:27:11.938Z
Modified
2026-08-18T03:31:14.405328955Z
Summary
uprobes: Fix NULL pointer dereference in hprobe_expire()
Details

In the Linux kernel, the following vulnerability has been resolved:

uprobes: Fix NULL pointer dereference in hprobe_expire()

Forking a task that has a pending uretprobe can oops the kernel with a NULL pointer dereference in the clone() path:

BUG: kernel NULL pointer dereference, address: 0000000000000018 Oops: 0002 [#1] SMP NOPTI RIP: 0010:hprobeexpire CR2: 0000000000000018 Call Trace: uprobecopyprocess copyprocess kernel_clone __x64sysclone dosyscall64 entrySYSCALL64afterhwframe

This was found on real hosts on Meta fleet.

I've got the impression that this is what is happening:

CPU 1 CPU 2 (traced task) ----- ------------------- hit uprobe, prepareuretprobe(): hprobe LEASED, refcount >= 1 uprobeunregister() putuprobe(): refcount -> 0 fork() -> duputask() hprobeexpire(hprobe, true) trygetuprobe() -> NULL getuprobe(NULL) <-- Oops

Only take the extra reference when the uprobe is non-NULL; a NULL means it is gone and is the correct value to return.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74477.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dd1a7567784e2b1f80258be04f57bcfa82c997eb
Fixed
3bd35a5e272a1b7a3fb43acad9bdc599281b13fa
Fixed
06c275a6c0a953ef1d763d11a6891fcc69ae2ac0
Fixed
cc679d7a6303e84d769f2afcde1fc51c51f127cd

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74477.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74477.json"