CVE-2026-74379: dax/kmem: account for partial discontiguous resource upon removal

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

dax/kmem: account for partial discontiguous resource upon removal

When devdaxkmemprobe() partially succeeds (at least one range is mapped) but a subsequent range fails requestmemregion() or addmemorydrivermanaged(), the probe silently continues, ultimately returning success, but with the corresponding range resource NULL'ed out.

devdaxkmemremove() iterates over all daxdevice ranges regardless of if the underlying resource exists. When removememory() is called later, it returns 0 because the memory was never added which causes devdaxkmemremove() to incorrectly assume the (nonexistent) resource can be removed and attempts cleanup on a NULL pointer.

Fix this by skipping these ranges altogether, noting that these cases are considered success, such that the cleanup is still reached when all actually-added ranges are successfully removed.

Event History

Aug 15, 2026
CVE Published
via MITRE·05:58 AM
Data Sourced
via MITRE·05:58 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203