Improper control of a resource through its lifetime in Linux kernel - CVE-2026-74487
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in binfmt_misc when removing an entry registered with the MISC_FMT_OPEN_FILE flag. A local user can register and remove such an entry to cause a denial of service.
The issue leaves the interpreter inode with a permanently negative write count until the inode is evicted from the inode cache, causing subsequent write attempts to fail with ETXTBSY.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74487
linux (Debian package) - update to 6.12.105-1