CVE-2026-74606
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
eventfs: Fix use-after-free in eventfs_remove_rec()<br />
<br />
eventfs_remove_rec() recursively removes the child at the current loop<br />
position. After the recursive call returns, list_for_each_entry() advances<br />
by reading list.next from the removed child.<br />
<br />
If free_ei() drops the final reference, release_ei() reuses the list/rcu<br />
union to queue an SRCU callback. The child may be freed before that read.<br />
The eventfs_mutex serializes list updates, but it does not keep the removed<br />
child alive or prevent the SRCU callback from running.<br />
<br />
Use list_for_each_entry_safe() to save the next sibling before recursively<br />
removing the current child.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/5635211b44969f4816e29ec4d5f8665fb39535d0
- https://git.kernel.org/stable/c/74bb1eaf72d185a78c879eb2678ea500f82f46a8
- https://git.kernel.org/stable/c/b77581b25e213e83b79ce11eb30024e55ceeb3e9
- https://git.kernel.org/stable/c/f161d7861a0bfdf10af6b738b3b57636204661fb
- https://git.kernel.org/stable/c/fd73b691702170d37d66f4b0278530cea8ed419a


