Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74642

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ALSA: usb: Fix UAF at delayed release of MIDI2 EPs<br /> <br /> The recent fix for UAF in ump_to_endpoint() caused another UAF because<br /> it tries to dereference the UMP endpoint object, but this might be<br /> executed at a delayed context where the endpoint has been already<br /> released.<br /> <br /> Add private_free to clear the associated data for avoiding the further<br /> dereference for delayed releases.

Impacto