{"id":"CVE-2026-74416","summary":"drm/radeon: fix memory leak in radeon_ring_restore() on lock failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/radeon: fix memory leak in radeon_ring_restore() on lock failure\n\nradeon_ring_restore() takes ownership of the data buffer allocated by\nradeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in\nthe non-restore branch; in the restore branch it relies on\nradeon_ring_restore() to free it.\n\nIf radeon_ring_lock() fails, the function returned early without calling\nkvfree(data), leaking the ring backup buffer on every GPU reset that\nfails at the lock stage. During repeated GPU resets this causes\ncumulative kernel memory exhaustion.\n\nFree data before returning the error.","modified":"2026-08-18T03:31:08.725534338Z","published":"2026-08-15T05:59:22.077Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74416.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/06dc892561f5a08b2493c34c8ec2cb94dea33159"},{"type":"WEB","url":"https://git.kernel.org/stable/c/07c213f3499dd72e2922c1c73fe9ffea24874bef"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1c9ba32308c02c198c378fcdf06be9ffc3111147"},{"type":"WEB","url":"https://git.kernel.org/stable/c/63912418f1fbb6456ea04bbcdf8f4d5090d23350"},{"type":"WEB","url":"https://git.kernel.org/stable/c/82f1d6042611d45b8b9de423bbcb4e0ced9ec62b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/919e3e398bf301c6418dffdcd5e5c4fd9be39cf7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ccc42187fc2d0720947a63ce1b9e399d2c068ff4"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eecfb76129ebef7e3aa41e18a4668cd91dfc6267"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74416.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74416"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"55d7c22192becd0ec827a6901899ff56fa985658"},{"fixed":"63912418f1fbb6456ea04bbcdf8f4d5090d23350"},{"fixed":"919e3e398bf301c6418dffdcd5e5c4fd9be39cf7"},{"fixed":"07c213f3499dd72e2922c1c73fe9ffea24874bef"},{"fixed":"1c9ba32308c02c198c378fcdf06be9ffc3111147"},{"fixed":"eecfb76129ebef7e3aa41e18a4668cd91dfc6267"},{"fixed":"06dc892561f5a08b2493c34c8ec2cb94dea33159"},{"fixed":"ccc42187fc2d0720947a63ce1b9e399d2c068ff4"},{"fixed":"82f1d6042611d45b8b9de423bbcb4e0ced9ec62b"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74416.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.6.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.97"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.40"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.5"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74416.json"}}],"schema_version":"1.9.0"}