Junglewise Threat Intelligence

CVE-2026-74313: Linux kernel vduse use-after-free in device open

CVE-2026-74313 · Severity: high · CVSS 8.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's VDUSE (vDPA Device in Userspace) driver contains a race condition that can lead to use-after-free when opening a virtual device. An attacker with local access can exploit concurrent operations to cause a kernel crash or potentially execute arbitrary code, affecting the stability and security of virtualization operations on the affected system.

Technical details

This is a use-after-free race condition in the VDUSE device open path (vduse_dev_open()). The vulnerability occurs because the function releases vduse_lock before acquiring dev->lock, creating a window where a concurrent VDUSE_DESTROY_DEV operation can remove and free the device object from the IDR (ID Radix tree) while the open path is still trying to access it. The fix maintains vduse_lock throughout the lookup and initial lock acquisition, ensuring atomicity. The vulnerability is exploitable with local access and requires the ability to trigger concurrent device open and destroy operations.

Affected products

  • Linux Linux kernel all versions with VDUSE support (introduced in v5.15 and later)

Timeline

  • 2026-08-15: disclosed: CVE-2026-74313 published
  • 2026-07-24: patched: Fix merged into Linux stable branches
  • 2026-05-08: other: Fix authored by Qihang Tang

References

Related threats