CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-74732

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check for tg ops in dce110_set_avmute Some older DCE timing generators do not implement is_tg_enabled in their ops table. Calling it unconditionally when waiting for AV mute frames causes a NULL pointer dereference on Southern Islands dGPUs when turning the display off over HDMI. Check that tg and the required ops exist before waiting for frames. (cherry picked from commit 2686a0c0aaa07bec2e24131835cf27b5fd4935a5)

CSIRTS triage

What
AMD display driver fails to check for tg (timing generator) operations, causing potential null pointer dereference.
Who is affected
Linux systems with AMD display devices and DRM display driver enabled.
Urgency
Moderate; CVSS 5.5 and null pointer dereference can crash the display subsystem.
Action
Apply kernel patch or upgrade to a Linux version with AMD display tg ops check.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-74732

Get an email if CVE-2026-74732 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-74732

CVE.org record

Embed the live status

CVE-2026-74732 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-74732 status](https://www.csirts.com/badge/CVE-2026-74732)](https://www.csirts.com/cve/CVE-2026-74732)