CVE-2026-74642
N/AIn the Linux kernel, the following vulnerability has been resolved: ALSA: usb: Fix UAF at delayed release of MIDI2 EPs The recent fix for UAF in ump_to_endpoint() caused another UAF because it tries to dereference the UMP endpoint object, but this might be executed at a delayed context where the endpoint has been already released. Add private_free to clear the associated data for avoiding the further dereference for delayed releases.
NO EXPLOITATION SIGNALS
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
—EPSS not yet scored
○ In CISA KEV
○ Public exploit / PoC
Impact if exploited
—CVSS · not scored
- No impact metrics
Proof of concept & exploit code
- github-search Search GitHub for public PoC repos
Test against your own equipment
curl -s https://vulnpedia.com/cve/CVE-2026-74642/poc.jsonMachine-readable PoC index for this CVE (for automation).Listed for defensive triage, patch verification, and authorized testing on systems you own. Machine-readable: /cve/CVE-2026-74642/poc.json
References
Technical & other
- https://git.kernel.org/stable/c/d431941825d357be7d9ab0cb7505e3a1963bd89e
- https://git.kernel.org/stable/c/422d8a02de5ce6a29d616d55e5ead5dec69ac1d7
- https://git.kernel.org/stable/c/d217d723c5e43881b952cdb978477f7f2dc0b6d7
- https://git.kernel.org/stable/c/f9d492a39ebeb1a56f13ec6dd165a18a48dec812
- https://git.kernel.org/stable/c/f8a80cfb68613fb7e6452b66447dbc63f435d140