CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74405

highCVSS 7.8covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: OPP: Fix race between OPP addition and lookup A race exists between dev_pm_opp_add_dynamic() and dev_pm_opp_find_freq_exact(): CPU0 (add) CPU1 (lookup) ------------------------------- ------------------------------ _opp_add() mutex_lock() list_add(&new_opp->node, head) mutex_unlock() _opp_table_find_key() mutex_lock() dev_pm_opp_get(opp) kref_get() mutex_unlock() kref_init(&new_opp->kref) dev_pm_opp_put() kref_put_mutex() The newly added OPP is inserted into the list before its kref is initialized. A concurrent lookup can find this OPP and increment its reference count while it is still uninitialized, leading to refcount corruption and a potential premature free. Fix this by initializing ->kref and ->opp_table before making the OPP visible via list_add(). This ensures any concurrent lookup observes a fully initialized object. [ Viresh: Updated commit log ]

CSIRTS triage

What
The OPP (Operating Performance Points) subsystem has a race condition between adding new operating points and looking them up.
Who is affected
Systems with dynamic voltage and frequency scaling (DVFS) enabled, common on mobile and embedded platforms.
Urgency
Medium severity (CVSS 4.1); no known exploitation but race conditions in frequency scaling can cause system instability.
Action
Apply kernel patch that synchronizes OPP addition and lookup operations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74405

Get an email if CVE-2026-74405 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74405

CVE.org record

Embed the live status

CVE-2026-74405 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74405 status](https://www.csirts.com/badge/CVE-2026-74405)](https://www.csirts.com/cve/CVE-2026-74405)