CVE-2026-74334
CVE CVE-2026-74334EUVD EUVD-2026-59481Published 2026-08-15T05:58:26.000ZLast changed 2026-08-17T05:46:03.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Fix locking when accessing mr->pd Sashiko points out that, due to rereg_mr, the PD is actually variable and all the touches in nldev are racy. Use mr->device instead of mr->pd->device. Getting the PD restrack ID is more tricky. To avoid disturbing all the happy paths, add an rdma_restrack_sync() operation which is sort of like flush_workqueue() or synchronize_irq(): after it returns, all the old nldev touches to the mr are gone and everything sees the new PD. This makes it safe to reach into the PD pointer.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; 4.18; patch: 7.2; da5c8507821573b8ed6e3f47e009f273493ffaf7 <1a132ee4e655288d9a0937ea5109a0d038431ae9; patch: 7.1.5; da5c8507821573b8ed6e3f47e009f273493ffaf7 <50d5c02ab8e62325548bd3a6e6b758a9dcd6e7c3
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.