Junglewise Threat Intelligence

CVE-2026-74363: Linux kernel bpffs use-after-free in inode freeing

CVE-2026-74363 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's BPF filesystem (bpffs) has a use-after-free vulnerability in inode memory management. When processes unlink BPF file objects while other tasks are still accessing them via RCU-based path walking, freed memory can be read, potentially leading to a system crash or memory corruption. This affects systems running affected kernel versions where BPF-based networking or security features are in use.

Technical details

The vulnerability is a use-after-free (UAF) in kernel/bpf/inode.c affecting bpffs inode lifecycle management. Root cause: a prior commit consolidated inode cleanup into destroy_inode() to avoid sleeping in RCU context, but removed the RCU grace period delay that protects inode metadata (i_opflags) and symlink body (i_link) accessed by concurrent RCU path walkers. An unlinkat() operation drops the last inode reference causing immediate freeing, while another CPU executing RCU pathwalk (pick_link, may_lookup, current_time) reads freed memory. The fix splits concerns: blocking cleanup (bpf_any_put) remains in destroy_inode() called immediately; inode/i_link freeing moved to new bpf_free_inode() called after RCU grace period. Precondition: concurrent operations on BPF filesystem objects. Patch available upstream and in stable kernels.

Affected products

  • Linux Linux kernel multiple versions; fixed in stable releases

Timeline

  • 2026-08-15: disclosed
  • 2026-06-02: patched: Upstream fix committed; backported to stable kernel branches

References

Related threats