CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74672

mediumCVSS 5.2covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: acquire init_mm lock on huge vmap to avoid ptdump UAF Patch series "mm: fix UAF caused by race between ptdump and vmap pgtable freeing", v6. Kernel page table walkers fall into two broad categories - those ranges where no exclusion is required via walk_kernel_page_table_range_lockless() and those where exclusion is required via walk_kernel_page_table_range() or walk_page_range_debug(). The former category is used only by arm64 arch code operating on ranges it both wholly owns and does not concurrently write. The latter category consists of kernel page table walkers operating on ranges that are wholly owned (but which need exclusion against concurrent writers). The lock used for exclusion is the mmap lock, and for kernel ranges this is the mmap lock on init_mm. ptdump is a special case being both the only user of walk_page_range_debug(), and the only case in which it walks ranges it does not own. This presents a problem, as page tables may be freed under ptdump. And indeed there is a use-after-free bug in the kernel as a result, which this series addresses. vmap promotes page tables to huge leaf entries where possible, freeing the lower page table when it does. It does this with no meaningful locks held against concurrent ptdump walks. As a result, use-after-free can currently occur. This series addresses the issue by having the vmap huge promotion logic acquire the mmap read lock while both setting the huge page table entry and freeing the prior leaf page table. The ptdump code already acquires the mmap write lock, so by doing so we ensure that the ptdump walker only ever observes either the huge page table entry or the existing page table entry, and nothing is freed underneath it. A mitigation for this issue was already applied for arm64 in commit fa93b45fd397 ("arm64: Enable vmalloc-huge with ptdump"), which this series has to deal with carefully. This mitigation resolv

CSIRTS triage

What
A use-after-free vulnerability in vmalloc huge vmap operations due to missing init_mm lock acquisition during ptdump traversal.
Who is affected
Linux kernel systems using vmalloc for large mappings that perform concurrent ptdump operations.
Urgency
Medium severity (CVSS 5.2) with no current exploitation; patch available upstream.
Action
Apply Linux kernel security patch addressing init_mm lock handling in mm/vmalloc.c.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74672

Get an email if CVE-2026-74672 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74672

CVE.org record

Embed the live status

CVE-2026-74672 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74672 status](https://www.csirts.com/badge/CVE-2026-74672)](https://www.csirts.com/cve/CVE-2026-74672)