CVE-2026-74617
In the Linux kernel, the following vulnerability has been resolved:
dibs: initialise dibs->lock in dibsdevalloc()
dibs->lock is initialised by dibsdevadd(), but a dibs device can
already take interrupts before that call: ism_probe() runs
ismdevinit(), and hence request_irq(), before it calls
dibsdevadd(). No client can have registered a dmb at that point, so
no dmb interrupt can occur, but a GID event interrupt can, and
ismhandleirq() takes dibs->lock unconditionally on entry, before it
inspects anything else.
Initialise the lock in dibsdevalloc() instead, so that it is valid as
soon as a driver can publish the device to its interrupt handler.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/2926031acba100d0c18fcfaa7a2ed29609318848, https://git.kernel.org/stable/c/c27e360545373b7aee9862a5beef3b9fb3df0c25, https://git.kernel.org/stable/c/fe79571f40434b257d68cbfb7b3ae93a794d8a11, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74617.json, https://nvd.nist.gov/vuln/detail/CVE-2026-74617, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git