๐Ÿ” CVE Alert

CVE-2026-74706

UNKNOWN 0.0

bnge: Fix NULL pointer dereference in aux device release

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback unconditionally dereferences aux_priv->auxr_dev->pdev to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated on this failure path, the dereference results in a NULL pointer exception Retrieve the parent bnge_dev from the auxiliary device's parent instead of auxr_dev, and free auxr_dev only when it was successfully allocated. This allows the release callback to correctly clean up partially initialized auxiliary devices.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554 < 83ef2f3cab7fe6dd9155cd598dc64be524d963a9 8ac050ec3b1c0dcb5e89cf86fe2ebe0afcc73554 < 1cb4298810e27e037d3ca07286ecbb97e89ba58d
Linux / Linux
6.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/83ef2f3cab7fe6dd9155cd598dc64be524d963a9 git.kernel.org: https://git.kernel.org/stable/c/1cb4298810e27e037d3ca07286ecbb97e89ba58d