PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74514 Linux CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-15T13:17:56.530Z and has not been modified since then. The CVE-2026-74514 vulnerability involves a memory accounting issue in the KVM s390 pci module of the Linux kernel. The account_mem() and unaccount_mem() functions call get_uid(), which increments the reference count of struct user_struct on every invocation, but the count is not decremented by calling free_uid(). Additionally, pages are accounted/unaccounted against the current->mm, but it's possible that unaccount_mem() can be called from a different process context than the one that originally pinned the pages. To fix this, the pinning process user_struct and mm_struct are stored when accounting for pinned pages, and these resources are freed when the pages are unpinned. This vulnerability affects Linux system administrators, KVM s390 pci module users, and organizations relying on Linux kernel-based infrastructure.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-23
Advisory published
2026-08-15
Advisory updated
2026-08-23

Who should care

Linux system administrators, KVM s390 pci module users, and organizations relying on Linux kernel-based infrastructure, particularly those with deployments using the Linux kernel, should be aware of this vulnerability and take necessary actions to mitigate potential risks. Those responsible for maintaining and securing Linux-based systems, especially in environments utilizing KVM s390 pci module, need to assess their exposure and apply appropriate patches or updates. Furthermore, security teams and vulnerability management teams should prioritize this issue due to its potential impact on system security and stability.

Technical summary

The CVE-2026-74514 vulnerability involves a memory accounting issue in the KVM s390 pci module of the Linux kernel. The account_mem() and unaccount_mem() functions call get_uid(), which increments the reference count of struct user_struct on every invocation, but the count is not decremented by calling free_uid(). Additionally, pages are accounted/unaccounted against the current->mm, but it's possible that unaccount_mem() can be called from a different process context than the one that originally pinned the pages. To fix this, the pinning process user_struct and mm_struct are stored when accounting for pinned pages, and these resources are freed when the pages are unpinned.

Defensive priority

This vulnerability affects the Linux kernel, specifically the KVM s390 pci module, and could potentially allow for memory corruption or privilege escalation.

Recommended defensive actions

  • Inventory Linux systems using KVM s390 pci module and assess for exposure.
  • Apply kernel updates or patches provided by the Linux distribution.
  • Monitor system logs for unusual memory allocation patterns.
  • Implement compensating controls such as memory access controls.
  • Exception tracking for systems with KVM s390 pci module.

Evidence notes

The CVE-2026-74514 vulnerability involves a memory accounting issue in the KVM s390 pci module of the Linux kernel. The account_mem() and unaccount_mem() functions call get_uid(), which increments the reference count of struct user_struct on every invocation, but the count is not decremented by calling free_uid(). Additionally, pages are accounted/unaccounted against the current->mm, but it's possible that unaccount_mem() can be called from a different process context than the one that originally pinned the pages. To fix this, the pinning process user_struct and mm_struct are stored when accounting for pinned pages, and these resources are freed when the pages are unpinned.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74514 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74514

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74514 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74514

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/36f6999ecde3976731a8bfc0b8e667da6f593069

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/47cfd75d9df7c8f425b0d769328fe43a8a8e606e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/70871b121f81d08879363cb1238a4c85c5c2800c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ad1c2ac7f15b224cf9ab26b593caa9bd1a4be72e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dc7465a364104526c56b922c9de9dfcc08a7d5f7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e3f732e086e438c52c7400bd2734bb166aa4752c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.