Improper resource shutdown or release in Linux kernel - CVE-2026-74484
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource shutdown in binfmt_misc 'F' entries when registering an entry whose interpreter points at the instance itself or uses the instance as an overlayfs lower layer. A local user can register a crafted binfmt_misc entry to cause a denial of service.
The issue can pin the binfmt_misc superblock and the user namespace, causing persistent resource consumption after the mount namespace is gone.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74484
linux (Debian package) - update to 6.12.105-1