Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74501

Published Aug 15, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-74501 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: fix use-after-free in ump_to_endpoint()

create_midi2_ump() registers a card-owned snd_ump_endpoint and stores a

back-pointer to its per-interface snd_usb_midi2_ump object in

ump->private_data, but it never installs an ump->private_free hook and

never clears that pointer.

If a later step of snd_usb_midi_v2_create() fails, its error path calls

free_all_midi2_umps(), which kfree()s the snd_usb_midi2_ump object while

the already-registered endpoint keeps pointing at it. The created

/dev/snd/umpC*D* node stays exposed, so the first operation of any UMP

open, ump_to_endpoint(), dereferences the dangling ump->private_data and

reads rmidi->eps[dir] out of freed memory.

A malicious USB MIDI 2.0 device that makes creation fail after the

endpoint is registered can thus trigger a slab use-after-free read on a

subsequent open of the UMP node.

Clear the endpoint's back-pointer before freeing the object, and le

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74501?

CVE-2026-74501 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-74501?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74501?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74501?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74501 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.