Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74504

Published Aug 15, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-74504 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Fix division by zero in initialize_timer()

A userspace-driven ALSA timer (SND_UTIMER) lets an unprivileged user set

the backing snd_timer's hardware resolution to an arbitrary 64-bit value

via SNDRV_TIMER_IOCTL_CREATE. snd_utimer_create() only rejects zero.

When such a timer is bound to a sequencer queue, initialize_timer()

computes the tick period as

tmr->ticks = 1000000000 / (r * freq);

where r is that user-controlled resolution and freq is the sequencer

update rate in Hz, clamped to MIN_FREQUENCY..MAX_FREQUENCY (10..6250).

A resolution of 2^63 makes the 64-bit product r * freq wrap to zero for

any even freq, including DEFAULT_FREQUENCY (1000), so the division faults

with a divide-by-zero.

The division runs under tmr->lock with interrupts disabled, so the oops

leaves the spinlock held and hangs the CPU. It is reachable by an

unprivileged user with access to /dev/snd/timer and /dev/snd/seq.

Oops:

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74504?

CVE-2026-74504 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-74504?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74504?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74504?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74504 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.