Junglewise Threat Intelligence

CVE-2026-74690: Linux kernel s390/ism use-after-free in device exit

CVE-2026-74690 · Severity: high · CVSS 8.4 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Internal Shared Memory (ISM) driver for IBM System z servers contains a race condition that allows interrupt handlers to access freed memory during device shutdown. When a device is removed, active interrupt handlers may attempt to access data structures that have already been deallocated, potentially causing kernel crashes or memory corruption. This vulnerability affects the stability and reliability of systems using shared memory for inter-process communication.

Technical details

The vulnerability is a use-after-free (UAF) race condition in the s390/ism driver's device exit path (ism_dev_exit). The vulnerable code freed the shared buffer array (sba) and interrupt event queue (ieq) data structures while interrupt handlers could still be executing concurrently and accessing them. The root cause is improper synchronization between unregister_ieq()/unregister_sba() calls and the actual memory deallocation. The fix reorders operations to call free_irq() after unregistering the interrupt sources, ensuring all in-flight interrupt handlers complete before memory is freed. The vulnerability is exploitable via device removal while the driver is actively processing interrupts, potentially leading to denial of service or privilege escalation from a local context.

Affected products

  • Linux Linux kernel All versions with s390/ism driver (introduced in commit 684b89bc39ce or later)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-06: patched: Fix committed upstream

References

Related threats