Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-74618
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper handling of a warning condition in binfmt_misc when completing an fscontext mount request from a different user namespace. A local user can pass an fscontext file descriptor across a namespace boundary and repeatedly trigger the warning to cause a denial of service.
The issue can be triggered in a loop to flood kernel logs, taint the kernel, and panic systems configured with panic_on_warn.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74618
linux (Debian package) - update to 6.12.105-1