CVE-2026-74642

Source
https://cve.org/CVERecord?id=CVE-2026-74642
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74642.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74642
Downstream
Published
2026-08-22T15:32:20Z
Modified
2026-08-24T11:47:15Z
Summary
ALSA: usb: Fix UAF at delayed release of MIDI2 EPs
Details

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb: Fix UAF at delayed release of MIDI2 EPs

The recent fix for UAF in ump_to_endpoint() caused another UAF because it tries to dereference the UMP endpoint object, but this might be executed at a delayed context where the endpoint has been already released.

Add private_free to clear the associated data for avoiding the further dereference for delayed releases.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74642.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
49eccef6d6e1c00dac6fb2e7eb6f9206c33e1c37
Fixed
d431941825d357be7d9ab0cb7505e3a1963bd89e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8a7a33b846d6ba695891b8d0040027cdbad8cd52
Fixed
422d8a02de5ce6a29d616d55e5ead5dec69ac1d7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cc014ebf803174f0e5d15956dfc5a38413c945ae
Fixed
d217d723c5e43881b952cdb978477f7f2dc0b6d7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ae388c0e1bf727972096f770f82d12e4f748d1b6
Fixed
f9d492a39ebeb1a56f13ec6dd165a18a48dec812
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a05b2d1b4642df74f30b6f54843e825c4a2bfd3
Fixed
f8a80cfb68613fb7e6452b66447dbc63f435d140

Affected versions

v6.*
v6.12.103
v6.18.44
v6.6.151
v7.*
v7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74642.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.151
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.12.103
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.18.44
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
7.1.8
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74642.json"