« Volver al listado

CVE-2026-74487

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: restore write access when removing an entry

Registering an entry with the MISC_FMT_OPEN_FILE flag opens the interpreter via open_exec() which denies write access to it for as long as the entry exists. Removing the entry closes the interpreter file via filp_close() but never restores write access, leaving the inode's i_writecount permanently negative. Opening the interpreter for writing keeps failing with ETXTBSY long after the entry is gone until the inode is evicted from the inode cache.

Commit 90f601b497d7 ("binfmt_misc: restore write access before closing files opened by open_exec()") fixed the same imbalance in the error path of bm_register_write() but the actual removal path has been leaking the write denial since the introduction of the flag.

Leer descripción completaMostrar menos

Restore write access in put_binfmt_handler() before closing the interpreter file.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74487",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "7873f987213695e3564c8c259e6db283e4739472",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "13efc628fdf641d901bdba07caa1c558e1bed046",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "f1cf67f6be0babc73afa4ee0e27bdedffeeeb095",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "fdc1d702bf3001586221fa07e598e876a0a854c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "3b522487a3a9162b1b519eefde7998d103e3e07b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "948b701a607f123df92ed29084413e5dd8cda2ed",
              "lessThan": "db1856ea9196cf6e015d12199a34c0b9313c7bfa",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/binfmt_misc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.266",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.217",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.153",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/binfmt_misc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:17:53.593",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/13efc628fdf641d901bdba07caa1c558e1bed046",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3b522487a3a9162b1b519eefde7998d103e3e07b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7873f987213695e3564c8c259e6db283e4739472",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/db1856ea9196cf6e015d12199a34c0b9313c7bfa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f1cf67f6be0babc73afa4ee0e27bdedffeeeb095",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fdc1d702bf3001586221fa07e598e876a0a854c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_misc: restore write access when removing an entry\n\nRegistering an entry with the MISC_FMT_OPEN_FILE flag opens the\ninterpreter via open_exec() which denies write access to it for as\nlong as the entry exists. Removing the entry closes the interpreter\nfile via filp_close() but never restores write access, leaving the\ninode's i_writecount permanently negative. Opening the interpreter\nfor writing keeps failing with ETXTBSY long after the entry is gone\nuntil the inode is evicted from the inode cache.\n\nCommit 90f601b497d7 (\"binfmt_misc: restore write access before\nclosing files opened by open_exec()\") fixed the same imbalance in the\nerror path of bm_register_write() but the actual removal path has\nbeen leaking the write denial since the introduction of the flag.\n\nRestore write access in put_binfmt_handler() before closing the\ninterpreter file."
    }
  ],
  "lastModified": "2026-08-23T13:16:44.750",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}