SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74606

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's eventfs subsystem, specifically in the eventfs_remove_rec() function, which can lead to a use-after-free condition. This flaw could allow an attacker to exploit the race condition, potentially leading to arbitrary code execution or system instability. Organizations using Linux-based systems, especially those relying on eventfs for event management, should prioritize patching this vulnerability to mitigate the associated risks.

CVE
CVE-2026-74606
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix use-after-free in eventfs_remove_rec() eventfs_remove_rec() recursively removes the child at the current loop position. After the recursive call returns, list_for_each_entry() advances by reading list.next from the removed child. If free_ei() drops the final reference, release_ei() reuses the list/rcu union to queue an SRCU callback. The child may be freed before that read. The eventfs_mutex serializes list updates, but it does not keep the removed child alive or prevent the SRCU callback from running. Use list_for_each_entry_safe() to save the next sibling before recursively removing the current child.