Race condition in Linux kernel - CVE-2026-74590

 

Race condition in Linux kernel - CVE-2026-74590

Published: August 24, 2026


Vulnerability identifier: #VU144969
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74590
CWE-ID: CWE-362
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to concurrent modification handling in bpf_get_fsverity_digest() when processing a dynptr-backed fsverity digest buffer. A local user can trigger the kfunc with a concurrently modified digest_size field to cause a denial of service.

The issue arises because the dynptr abstraction ensures memory validity but not stability of its contents during concurrent access.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74590

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins