Use-after-free in Linux kernel - CVE-2026-74363
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in bpffs inode handling when a concurrent unlinkat() drops the last inode reference during RCU path walking. A local user can trigger concurrent path operations to cause a denial of service.
The issue occurs because inode fields and the cached symlink body may still be accessed during RCU pathwalk after the inode is freed.
Affected software
openEuler
kernel
bpftool
bpftool-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-devel
kernel-extra-modules
kernel-headers
kernel-source
kernel-tools
kernel-tools-debuginfo
kernel-tools-devel
perf
perf-debuginfo
python3-perf
python3-perf-debuginfo
How to mitigate CVE-2026-74363
kernel - update to 6.6.0-145.3.29.160
bpftool - update to 6.6.0-145.3.29.160
bpftool-debuginfo - update to 6.6.0-145.3.29.160
kernel-debuginfo - update to 6.6.0-145.3.29.160
kernel-debugsource - update to 6.6.0-145.3.29.160
kernel-devel - update to 6.6.0-145.3.29.160
kernel-extra-modules - update to 6.6.0-145.3.29.160
kernel-headers - update to 6.6.0-145.3.29.160
kernel-source - update to 6.6.0-145.3.29.160
kernel-tools - update to 6.6.0-145.3.29.160
kernel-tools-debuginfo - update to 6.6.0-145.3.29.160
kernel-tools-devel - update to 6.6.0-145.3.29.160
perf - update to 6.6.0-145.3.29.160
perf-debuginfo - update to 6.6.0-145.3.29.160
python3-perf - update to 6.6.0-145.3.29.160
python3-perf-debuginfo - update to 6.6.0-145.3.29.160
External References
- https://git.kernel.org/stable/c/0497ff765746d9b2d17445c8f7cc737b36c0152a
- https://git.kernel.org/stable/c/53649846e0437d1d9b7cb993cfe54c367addf7ae
- https://git.kernel.org/stable/c/5fecb71c10c28aef276ba49c718dc961745fdcf0
- https://git.kernel.org/stable/c/61f19729728243c82476dee31315143ed3275e7f
- https://git.kernel.org/stable/c/b93c55b4932dd7e32dca8cf34a3443cc87a02906
- https://git.kernel.org/stable/c/c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2
- https://git.kernel.org/stable/c/ea1c243c39e32b7fc1c2edfe32081ff7e30a877c