« Volver al listado

CVE-2026-74370

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

liveupdate: fix TOCTOU race in luo_session_retrieve()

Extend the scope of the rwsem_read lock in luo_session_retrieve() to overlap with the acquisition of the session mutex. This prevents a concurrent thread from releasing and freeing the session between the lookup and the mutex lock.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74370",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0153094d03df5a2e834a19c59b255649a258ae46",
              "lessThan": "d944170607b872a1f93713c555ad3f0efde3a9b8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0153094d03df5a2e834a19c59b255649a258ae46",
              "lessThan": "d3ae9e7fddb4036f50003d7fa1ef52801fdb961b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/liveupdate/luo_session.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/liveupdate/luo_session.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:38.750",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/d3ae9e7fddb4036f50003d7fa1ef52801fdb961b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d944170607b872a1f93713c555ad3f0efde3a9b8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nliveupdate: fix TOCTOU race in luo_session_retrieve()\n\nExtend the scope of the rwsem_read lock in luo_session_retrieve() to\noverlap with the acquisition of the session mutex. This prevents a\nconcurrent thread from releasing and freeing the session between the\nlookup and the mutex lock."
    }
  ],
  "lastModified": "2026-08-17T06:19:31.823",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}