{"apiVersion":"1.0","identifier":"CVE-2026-74706","description":"In the Linux kernel, the following vulnerability has been resolved: bnge: Fix NULL pointer dereference in aux device release If allocation of auxr_dev fails during auxiliary device setup, the error path calls auxiliary_device_uninit(), which eventually invokes bnge_aux_dev_release(). The release callback unconditionally dereferences aux_priv->auxr_dev->pdev to retrieve the parent bnge_dev. Since auxr_dev has not yet been allocated on this failure path, the dereference results in a NULL pointer exception Retrieve the parent bnge_dev from the auxiliary device-s parent instead of auxr_dev, and free auxr_dev only when it was successfully allocated. This allows the release callback to correctly clean up partially initialized auxiliary devices.","publishedAt":"2026-08-22T16:16:45","lastModifiedAt":"2026-08-22T16:16:45","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74706","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00156,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74706","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74706","en":"https://www.redsauce.net/en/cves/CVE-2026-74706","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74706","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74706","de":"https://www.redsauce.net/de/cves/CVE-2026-74706","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74706","el":"https://www.redsauce.net/el/cves/CVE-2026-74706"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74706"}}