CVE-2026-74416: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure

Published Aug 15, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

drm/radeon: fix memory leak in radeonringrestore() on lock failure

radeonringrestore() takes ownership of the data buffer allocated by radeonringbackup(). The caller (radeongpureset()) only frees it in the non-restore branch; in the restore branch it relies on radeonringrestore() to free it.

If radeonringlock() fails, the function returned early without calling kvfree(data), leaking the ring backup buffer on every GPU reset that fails at the lock stage. During repeated GPU resets this causes cumulative kernel memory exhaustion.

Free data before returning the error.

Affected Software

1 affected component
Linux kernel drm/radeon

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update the Linux kernel DRM Radeon code so that radeon_ring_restore() frees the ring backup buffer (data) when radeon_ring_lock() fails, preventing cumulative kernel memory exhaustion during repeated GPU resets.

    Linux kernel drm/radeon Fix memory leak in radeon_ring_restore() on lock failure = Apply upstream patch that adds missing kvfree(data)/frees ring backup buffer on radeon_ring_lock() failure

Event History

Aug 15, 2026
CVE Published
via MITRE·05:59 AM
Data Sourced
via MITRE·05:59 AM
Description
Data Sourced
via NVD·06:22 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2026-74416?

The severity of CVE-2026-74416 is rated as risk 23.

2

How do I fix CVE-2026-74416?

To fix CVE-2026-74416, update to the latest Linux kernel version that includes the patch for this vulnerability.

3

What component is affected by CVE-2026-74416?

CVE-2026-74416 affects the DRM (Direct Rendering Manager) component of the Linux kernel.

4

What type of vulnerability is CVE-2026-74416?

CVE-2026-74416 is a memory leak vulnerability that occurs in the radeon_ring_restore() function.

5

When was CVE-2026-74416 published?

CVE-2026-74416 was published on August 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203