{"id":"CVE-2026-74606","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74606","summary":"eventfs: Fix use-after-free in eventfs_remove_rec()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Fix use-after-free in eventfs_remove_rec()\n\neventfs_remove_rec() recursively removes the child at the current loop\nposition. After the recursive call returns, list_for_each_entry() advances\nby reading list.next from the removed child.\n\nIf free_ei() drops the final reference, release_ei() reuses the list/rcu\nunion to queue an SRCU callback. The child may be freed before that read.\nThe eventfs_mutex serializes list updates, but it does not keep the removed\nchild alive or prevent the SRCU callback from running.\n\nUse list_for_each_entry_safe() to save the next sibling before recursively\nremoving the current child.","published":"2026-08-22T15:31:53.819Z","modified":"2026-08-24T11:46:58.363522036Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.152"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/5635211b44969f4816e29ec4d5f8665fb39535d0"},{"type":"WEB","url":"https://git.kernel.org/stable/c/74bb1eaf72d185a78c879eb2678ea500f82f46a8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b77581b25e213e83b79ce11eb30024e55ceeb3e9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/f161d7861a0bfdf10af6b738b3b57636204661fb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/fd73b691702170d37d66f4b0278530cea8ed419a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74606.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74606"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T11:46:58.363522036Z"}}