CVE-2026-74442
CVE CVE-2026-74442EUVD EUVD-2026-59749Published 2026-08-15T12:26:50.000ZLast changed 2026-08-17T05:19:29.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure Two paths through vmw_vkms_init() can leave vmw->crc_workq NULL while still leaving the rest of the driver in a state that calls vmw_vkms_cleanup() at module unload: 1. vmw_host_get_guestinfo(GUESTINFO_VBLANK, ...) failing or returning an oversized buffer -- the common case on hosts without a VBLANK guestinfo entry -- early-returned before the workqueue allocation. 2. alloc_ordered_workqueue() returning NULL on memory pressure. vmw_vkms_cleanup() then calls destroy_workqueue(NULL), which dereferences wq->name and panics. Fix the first case by removing the early return: vmw->vkms_enabled is already false on the rpci-failure path so no work will ever be queued, and allocating the workqueue unconditionally keeps the control flow simple. Fix the second case by guarding the cleanup with a NULL check, since alloc_ordered_workqueue() can still fail under low memory.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 6.10; patch: 6.12.103; patch: 7.2; patch: 7.1.8; 7b0062036c3b71b4a69e244ecf0502c06c4cf5f0 <0ee0532f1d405d37f38c44cbba87342e63d3bbd4; 7b0062036c3b71b4a69e244ecf0502c06c4cf5f0 <7c701778c6a369769992614dac8dc00c8ac72afc; patch: 0; 7b0062036c3b71b4a69e244ecf0502c06c4cf5f0 <05eaa887e7b4f40fba425f8a1d7a5a8a043092a6; patch: 6.18.44; 7b0062036c3b71b4a69e244ecf0502c06c4cf5f0 <96efee36453b697ccbaf75091b7a1807c11809dd
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.