PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74472 Linux CVE debrief

The Linux kernel vulnerability CVE-2026-74472 was resolved by resetting kernel-owned dev_info fields in ublk_ctrl_add_dev(). The vulnerability allowed a device to be added with an incorrect state, causing issues with disk detachment and char device read/write paths. This issue was caused by the ublk_ctrl_add_dev() function failing to reset kernel-owned dev_info fields. Affected Linux kernel developers and administrators should review and apply the patch to prevent potential issues. The vulnerability was introduced in the Linux kernel's ublk_ctrl_add_dev() function, which failed to reset kernel-owned dev_info fields. This caused issues with device state and disk detachment. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). To verify, defenders should review the patch and check for potential issues with char device read/write paths. Additionally, they should monitor for device state and disk detachment issues in the Linux kernel. The patch fixes the issue by ensuring that kernel-owned dev_info fields are properly reset, preventing incorrect device states and associated problems.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, administrators who use the Linux kernel, and security teams responsible for vulnerability management and patching should be aware of this vulnerability and take necessary actions to mitigate it. They should review the patch and verify device state and disk detachment in the Linux kernel. Additionally, they should monitor for potential issues with char device read/write paths and review compensating controls for exposed systems.

Technical summary

The Linux kernel vulnerability CVE-2026-74472 was caused by the ublk_ctrl_add_dev() function failing to reset kernel-owned dev_info fields. This allowed a device to be added with an incorrect state, causing issues with disk detachment and char device read/write paths. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). Affected Linux kernel developers and administrators should review and apply the patch to prevent potential issues.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the patch to reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
  • Verify device state and disk detachment in the Linux kernel
  • Monitor for potential issues with char device read/write paths
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was introduced in the Linux kernel's ublk_ctrl_add_dev() function, which failed to reset kernel-owned dev_info fields. This caused issues with device state and disk detachment. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). To verify, defenders should review the patch and check for potential issues with char device read/write paths. Additionally, they should monitor for device state and disk detachment issues in the Linux kernel.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74472 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74472

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74472 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74472

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.