SB20260824216 - Use-after-free in Linux kernel tracefs
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74606)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in eventfs_remove_rec() in fs/tracefs/event_inode.c when recursively removing eventfs child entries. A local user can trigger recursive removal of crafted eventfs entries to cause a denial of service.
The issue occurs because iteration continues by reading the next list pointer from a child entry after that child has been removed and may already have been freed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/5635211b44969f4816e29ec4d5f8665fb39535d0
- https://git.kernel.org/stable/c/74bb1eaf72d185a78c879eb2678ea500f82f46a8
- https://git.kernel.org/stable/c/b77581b25e213e83b79ce11eb30024e55ceeb3e9
- https://git.kernel.org/stable/c/f161d7861a0bfdf10af6b738b3b57636204661fb
- https://git.kernel.org/stable/c/fd73b691702170d37d66f4b0278530cea8ed419a