CVE-2026-74687 PUBLISHED

watchdog: at91sam9_wdt: prevent timer rearm during teardown

Assigner: Linux
Reserved: 15.08.2026 Published: 22.08.2026 Updated: 22.08.2026

In the Linux kernel, the following vulnerability has been resolved:

watchdog: at91sam9_wdt: prevent timer rearm during teardown

at91_ping() rearms the watchdog timer from its callback. timer_delete() neither waits for a running callback nor prevents it from rearming the timer, so probe failure or driver removal can leave the timer accessing the devm-allocated at91wdt after it has been freed.

Use timer_shutdown_sync() on both teardown paths. It waits for a running callback and rejects any attempt by the callback to rearm the timer.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5161b31dc39a6d6dadc95f298de48a725b73ada8 to 29fe74c9aa69d78c1c6a3930f1d9fc5db71a6eed (excl.)
  • affected from 5161b31dc39a6d6dadc95f298de48a725b73ada8 to b7949b0a7d998013b7ec8617a0ef5b07cca80be4 (excl.)
  • affected from 5161b31dc39a6d6dadc95f298de48a725b73ada8 to 8444d66aa6b6e7fe0a26fa1a00a11cb4d0523783 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.14 is affected
  • unaffected from 0 to 3.14 (excl.)
  • unaffected from 6.18.45 to 6.18.* (incl.)
  • unaffected from 7.1.9 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References