CVE-2026-74461
Linux i2c_imx driver NULL-deref can crash kernels on i.MX devices.
Is CVE-2026-74461 being exploited?
Not confirmed. CVE-2026-74461 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.14% probability of exploitation in the next 30 days.
How severe is CVE-2026-74461?
CVE-2026-74461 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74461?
Yes. A fix has been recorded for CVE-2026-74461. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74461 affect?
CVE-2026-74461 affects Linux kernel (i2c_imx driver), NXP i.MX SoC-based devices, Embedded Linux / IoT devices. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74461?
Apply vendor/kernel patch and reboot; restrict access to /dev/i2c-* if needed.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local user or connected device can trigger use-after-free/NULL deref in i2c_imx, causing kernel crash (DoS); may enable privilege escalation on some SoCs.
Patch when possible
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < e3da77bdb4015051656bb472c295656bbea03b6f
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < 470fe15fb3bb2eba6629be301ca7e991ee3cfb7e
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < a8a1f9ac3d763e721586f15479ef9140b216ddf3
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < 753060f2b77ff2f386addbd3ecadb95b9f90cddd
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < affd62f5719a78135b7441aa49c8cab3c3b5e838
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < dab4762ee7f3fd0a01980d5407ba48d0261d3bff
- affected>= f7414cd6923fd7f78e57086fc964ba2dc25db5c1 and < 6ac7702b6cc2b94aaed9ef2d95bfbefcdc90061f
- affected5.11
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.