Junglewise Threat Intelligence

CVE-2026-74329: Linux kernel watchdog use-after-free via stale PM notifier

CVE-2026-74329 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's watchdog driver fails to properly clean up a power management notification handler when a watchdog device is unregistered. This leaves a dangling reference that can be triggered during system suspend/resume cycles, potentially causing system crashes or memory corruption on any Linux system using watchdog devices with suspend-time protection enabled.

Technical details

The vulnerability is a use-after-free in the watchdog subsystem's PM notifier handling. When watchdog_register_device() is called with the WDOG_NO_PING_ON_SUSPEND flag set, it registers a power management notifier block (wdd->pm_nb). However, watchdog_unregister_device() fails to unregister this PM notifier before tearing down the watchdog device and clearing wdd->wd_data. A subsequent system suspend/resume cycle triggers the stale notifier, calling watchdog_pm_notifier() with either a freed watchdog_device pointer or after critical data structures have been cleared. The fix adds an unregister_pm_notifier() call in __watchdog_unregister_device() before calling watchdog_dev_unregister(). This is a local attack surface requiring system suspend access but no elevated privileges.

Affected products

  • Linux Linux kernel multiple versions prior to upstream commit a298c7302ee9584a7a1ac1e8acbede8d98ab51a4

Timeline

  • 2026-08-15: disclosed
  • 2026-06-01: patched: Upstream fix committed by Yuho Choi
  • 2026-08-15: advisory

References

Related threats