Junglewise Threat Intelligence

CVE-2026-74629: Linux kernel dibs device double free and use-after-free

CVE-2026-74629 · Severity: high · CVSS 8.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's dibs (Distributed In-Kernel Byte Stream) device driver contains two related memory management flaws in the dmb_clientid_arr array. An interrupt handler may access freed memory after the device is removed, and initialization failures cause the same buffer to be freed twice, potentially corrupting kernel memory or causing a crash.

Technical details

The vulnerability involves use-after-free (UAF) and double-free flaws in the dibs device driver's memory management. The dmb_clientid_arr array is freed in dibs_dev_del() while the device interrupt handler may still access it afterward. Additionally, if dibs_dev_add() fails, the array is freed in error handling within that function; if dibs_dev_del() is later called, it attempts to free the already-freed pointer again. The fix defers freeing dmb_clientid_arr until dibs_dev_release() is called (after the last reference to the device is dropped), ensuring the interrupt handler cannot race with deallocation and preventing double-free in error paths. Attack vector requires local access with ability to trigger device probe failures or remove operations.

Affected products

  • Linux Linux kernel multiple versions (patch available in stable branches and mainline)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-10: patched: Patch committed to upstream (9e6869be49064915edb6c8776b27c376cfdb0df5); merged to stable branches
  • 2026-08-19: other: Patch included in stable kernel releases by Greg Kroah-Hartman

References

Related threats