Junglewise Threat Intelligence

CVE-2026-74606: Linux kernel eventfs use-after-free in removal

CVE-2026-74606 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's eventfs tracing filesystem contains a use-after-free vulnerability in the event removal function. An attacker with local access to the kernel can trigger this flaw by causing the removal of nested event files to corrupt memory, potentially leading to privilege escalation or denial of service.

Technical details

The vulnerability is a use-after-free (CWE-416) in the eventfs_remove_rec() function, which recursively removes eventfs_inode structures. The function uses list_for_each_entry() to iterate over child inodes; after recursively removing a child, the loop attempts to advance by reading list.next from the already-freed child node. When free_ei() drops the final reference, release_ei() reuses the list/rcu union for queuing an SRCU callback, allowing the child to be freed before the list pointer read occurs. The eventfs_mutex does not prevent this race condition. The fix replaces list_for_each_entry() with list_for_each_entry_safe(), which saves the next sibling pointer before the recursive removal. This vulnerability affects multiple kernel versions and is marked for stable backports.

Affected products

  • Linux Linux kernel multiple versions (introduced by commit 43aa6f97c2d0, fixed via commit fd73b691702170d37d66f4b0278530cea8ed419a)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-19: patched

References

Related threats