CVE-2026-74505

Source
https://cve.org/CVERecord?id=CVE-2026-74505
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74505.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74505
Downstream
Published
2026-08-15T12:27:29.436Z
Modified
2026-08-19T03:48:57.720112420Z
Summary
ALSA: 6fire: Fix UAF at error handling during probe
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: 6fire: Fix UAF at error handling during probe

Although 6fire driver had a few fixes for dealing with the early error handling during the probe phase, it forgot a pending URB before freeing the resources, which may lead to a UAF.

This patch addresses it by doing the almost same cleanup procedure like the normal disconnect phase at the error path.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74505.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c6d43ba816d1cf1d125bfbfc938f2a28a87facf9
Fixed
49bc7741cd2761c703a292dc69245041ae8a67bd
Fixed
2de734dcbb210bd59983e13d36988acbcc122194
Fixed
11e2953d9f4c7c3d2af94a889c2d805c537d633f
Fixed
630c8d6a93cbd9b2a207f1a67ef1fd21af098b0c
Fixed
a54bf16965f896415c3337bc4fbb40fb11941d99

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74505.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.39
Fixed
6.6.151
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.103
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74505.json"