CVE-2026-74606

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/08/2026
Last modified:
22/08/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> eventfs: Fix use-after-free in eventfs_remove_rec()<br /> <br /> eventfs_remove_rec() recursively removes the child at the current loop<br /> position. After the recursive call returns, list_for_each_entry() advances<br /> by reading list.next from the removed child.<br /> <br /> If free_ei() drops the final reference, release_ei() reuses the list/rcu<br /> union to queue an SRCU callback. The child may be freed before that read.<br /> The eventfs_mutex serializes list updates, but it does not keep the removed<br /> child alive or prevent the SRCU callback from running.<br /> <br /> Use list_for_each_entry_safe() to save the next sibling before recursively<br /> removing the current child.

Impact