Skip to main content
EPSS 0.2%top 90%

Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepoint null pointer dereferences… (CVE-2026-74418)

0
Medium
Published: 08/17/2026 (08/17/2026, 00:00:00 UTC)
Source: GCVE Database
Product: linux-hwe-edge

Description

In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepoint null pointer dereferences Trace_dma_fence_signaled, trace_dma_fence_wait_end and trace_dma_fence_destroy can all currently dereference a null fence->ops pointer after it has been reset on fence signalling. Lets use the safe string getters for most tracepoints to avoid this class of a problem, while for the signal tracepoint we move it to before ops are cleared to avoid losing the driver and timeline name information. Apart from moving it we also need to add a new tracepoint class to bypass the safe name getters since the signaled bit is already set. For dma_fence_init we also need to use the new tracepoint class since the rcu read lock is not held there, and we can do the same for the enable signaling since there we are certain the fence cannot be signaled while we are holding the lock and have even validated the fence->ops.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 15:59:28 UTC

Technical Analysis

The Linux kernel's dma-fence subsystem had a vulnerability involving potential null pointer dereferences in tracepoints related to fence signaling. Specifically, the trace_dma_fence_signaled, trace_dma_fence_wait_end, and trace_dma_fence_destroy functions could dereference a null fence->ops pointer after it was reset during fence signaling. The fix involved using safe string getters for most tracepoints to avoid null pointer dereferences, moving the signal tracepoint to before ops are cleared to retain driver and timeline name information, and introducing a new tracepoint class to bypass safe name getters when the signaled bit is set. Additional adjustments were made for dma_fence_init and enable signaling to ensure safe operation without holding the RCU read lock and to validate fence->ops.

Potential Impact

The vulnerability could cause null pointer dereferences in the Linux kernel's dma-fence tracepoints, potentially leading to kernel crashes or instability. There is no information about exploitation in the wild or direct security impact such as privilege escalation or data leakage. The issue primarily affects kernel stability and reliability during fence signaling operations.

Mitigation Recommendations

A fix for this vulnerability has been implemented in the Linux kernel by modifying the dma-fence tracepoint handling to prevent null pointer dereferences. Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided, check the Linux kernel mailing lists or official repositories for the relevant patch and update guidance. Patch status is not yet confirmed in this data — verify with the vendor advisory for current remediation instructions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-34jm-85m6-f5hv
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74418"]

Threat ID: 6a808b68bf8831d5394f56b4

Added to database: 08/15/2026, 15:53:12 UTC

Last enriched: 08/15/2026, 15:59:28 UTC

Last updated: 09/30/2026, 03:28:30 UTC

Views: 27

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses