Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74487

 

Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74487

Published: August 16, 2026


Vulnerability identifier: #VU143296
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74487
CWE-ID: CWE-664
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper resource management in binfmt_misc when removing an entry registered with the MISC_FMT_OPEN_FILE flag. A local user can register and remove such an entry to cause a denial of service.

The issue leaves the interpreter inode with a permanently negative write count until the inode is evicted from the inode cache, causing subsequent write attempts to fail with ETXTBSY.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74487

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins