Race condition in Linux kernel - CVE-2026-74590
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to concurrent modification handling in bpf_get_fsverity_digest() when processing a dynptr-backed fsverity digest buffer. A local user can trigger the kfunc with a concurrently modified digest_size field to cause a denial of service.
The issue arises because the dynptr abstraction ensures memory validity but not stability of its contents during concurrent access.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74590
linux (Debian package) - update to 6.12.105-1