Junglewise Threat Intelligence

CVE-2026-74418: Linux kernel dma-fence null pointer dereference in tracepoints

CVE-2026-74418 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Direct Memory Access (DMA) fence implementation contains a flaw in its diagnostic logging (tracepoints) where null pointer references can occur after fence operations are reset. This can cause the kernel to crash or become unstable, potentially resulting in system downtime or data loss for workloads relying on GPU or DMA operations.

Technical details

The vulnerability is a null pointer dereference in three tracepoints: trace_dma_fence_signaled, trace_dma_fence_wait_end, and trace_dma_fence_destroy. These functions attempt to access fence->ops after it has been reset to NULL during fence signaling. The root cause lies in a prior commit (541c8f2468b9) that detaches fence ops on signal. The fix involves moving the signaled tracepoint call to before ops are cleared, using safe string getters for other tracepoints to handle null ops pointers, and introducing a new tracepoint event class for call sites where the RCU read lock is held and fence->ops is guaranteed valid. No authentication or network access is required to trigger this; it can occur during normal DMA fence signaling operations.

Affected products

  • Linux Linux kernel Multiple versions (see git stable tree)

Timeline

  • 2026-04-15: disclosed
  • 2026-07-24: patched

References

Related threats