๐Ÿ” CVE Alert

CVE-2026-74405

UNKNOWN 0.0

OPP: Fix race between OPP addition and lookup

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: OPP: Fix race between OPP addition and lookup A race exists between dev_pm_opp_add_dynamic() and dev_pm_opp_find_freq_exact(): CPU0 (add) CPU1 (lookup) ------------------------------- ------------------------------ _opp_add() mutex_lock() list_add(&new_opp->node, head) mutex_unlock() _opp_table_find_key() mutex_lock() dev_pm_opp_get(opp) kref_get() mutex_unlock() kref_init(&new_opp->kref) dev_pm_opp_put() kref_put_mutex() The newly added OPP is inserted into the list before its kref is initialized. A concurrent lookup can find this OPP and increment its reference count while it is still uninitialized, leading to refcount corruption and a potential premature free. Fix this by initializing ->kref and ->opp_table before making the OPP visible via list_add(). This ensures any concurrent lookup observes a fully initialized object. [ Viresh: Updated commit log ]

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7034764a1e4a6edbb60914e89aad8384e3fe5d17 < 46696b0b2123475d7f95909435c09808fc5ffd23 7034764a1e4a6edbb60914e89aad8384e3fe5d17 < bb75bd7d9ae7672034f73ce67a57e6ac89bb39e5 7034764a1e4a6edbb60914e89aad8384e3fe5d17 < f5e1cc9a284bff2510981643a5bca4bc4c21b81a
Linux / Linux
4.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/46696b0b2123475d7f95909435c09808fc5ffd23 git.kernel.org: https://git.kernel.org/stable/c/bb75bd7d9ae7672034f73ce67a57e6ac89bb39e5 git.kernel.org: https://git.kernel.org/stable/c/f5e1cc9a284bff2510981643a5bca4bc4c21b81a