PatchSiren cyber security CVE debrief
CVE-2026-74472 Linux CVE debrief
The Linux kernel vulnerability CVE-2026-74472 was resolved by resetting kernel-owned dev_info fields in ublk_ctrl_add_dev(). The vulnerability allowed a device to be added with an incorrect state, causing issues with disk detachment and char device read/write paths. This issue was caused by the ublk_ctrl_add_dev() function failing to reset kernel-owned dev_info fields. Affected Linux kernel developers and administrators should review and apply the patch to prevent potential issues. The vulnerability was introduced in the Linux kernel's ublk_ctrl_add_dev() function, which failed to reset kernel-owned dev_info fields. This caused issues with device state and disk detachment. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). To verify, defenders should review the patch and check for potential issues with char device read/write paths. Additionally, they should monitor for device state and disk detachment issues in the Linux kernel. The patch fixes the issue by ensuring that kernel-owned dev_info fields are properly reset, preventing incorrect device states and associated problems.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-15
- Original CVE updated
- 2026-08-15
- Advisory published
- 2026-08-15
- Advisory updated
- 2026-08-15
Who should care
Linux kernel developers, administrators who use the Linux kernel, and security teams responsible for vulnerability management and patching should be aware of this vulnerability and take necessary actions to mitigate it. They should review the patch and verify device state and disk detachment in the Linux kernel. Additionally, they should monitor for potential issues with char device read/write paths and review compensating controls for exposed systems.
Technical summary
The Linux kernel vulnerability CVE-2026-74472 was caused by the ublk_ctrl_add_dev() function failing to reset kernel-owned dev_info fields. This allowed a device to be added with an incorrect state, causing issues with disk detachment and char device read/write paths. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). Affected Linux kernel developers and administrators should review and apply the patch to prevent potential issues.
Defensive priority
Medium
Recommended defensive actions
- Review and apply the patch to reset kernel-owned dev_info fields in ublk_ctrl_add_dev()
- Verify device state and disk detachment in the Linux kernel
- Monitor for potential issues with char device read/write paths
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The vulnerability was introduced in the Linux kernel's ublk_ctrl_add_dev() function, which failed to reset kernel-owned dev_info fields. This caused issues with device state and disk detachment. The vulnerability was resolved by resetting the kernel-owned dev_info fields in ublk_ctrl_add_dev(). To verify, defenders should review the patch and check for potential issues with char device read/write paths. Additionally, they should monitor for device state and disk detachment issues in the Linux kernel.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-74472 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-74472
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-74472 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74472
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.