« Volver al listado

CVE-2026-74606

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix use-after-free in eventfs_remove_rec()

eventfs_remove_rec() recursively removes the child at the current loop position. After the recursive call returns, list_for_each_entry() advances by reading list.next from the removed child.

If free_ei() drops the final reference, release_ei() reuses the list/rcu union to queue an SRCU callback. The child may be freed before that read. The eventfs_mutex serializes list updates, but it does not keep the removed child alive or prevent the SRCU callback from running.

Use list_for_each_entry_safe() to save the next sibling before recursively removing the current child.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L, PR:L) de use-after-free en kernel Linux que permite DoS o ejecución de código con privilegios elevados; la pista sugiere T1068 (escalada local).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74606",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5dfb04100326f70e3b2d2872c2476ed20b804837",
              "lessThan": "b77581b25e213e83b79ce11eb30024e55ceeb3e9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "43aa6f97c2d03a52c1ddb86768575fc84344bdbb",
              "lessThan": "f161d7861a0bfdf10af6b738b3b57636204661fb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "43aa6f97c2d03a52c1ddb86768575fc84344bdbb",
              "lessThan": "5635211b44969f4816e29ec4d5f8665fb39535d0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "43aa6f97c2d03a52c1ddb86768575fc84344bdbb",
              "lessThan": "74bb1eaf72d185a78c879eb2678ea500f82f46a8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "43aa6f97c2d03a52c1ddb86768575fc84344bdbb",
              "lessThan": "fd73b691702170d37d66f4b0278530cea8ed419a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5a43badefe0eccca0c26144c0a44b8d417ce8103",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.18",
              "lessThan": "6.6.152",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.7.6",
              "lessThan": "6.8",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/tracefs/event_inode.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.8",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/tracefs/event_inode.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:33.077",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5635211b44969f4816e29ec4d5f8665fb39535d0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/74bb1eaf72d185a78c879eb2678ea500f82f46a8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b77581b25e213e83b79ce11eb30024e55ceeb3e9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f161d7861a0bfdf10af6b738b3b57636204661fb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fd73b691702170d37d66f4b0278530cea8ed419a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\neventfs: Fix use-after-free in eventfs_remove_rec()\n\neventfs_remove_rec() recursively removes the child at the current loop\nposition. After the recursive call returns, list_for_each_entry() advances\nby reading list.next from the removed child.\n\nIf free_ei() drops the final reference, release_ei() reuses the list/rcu\nunion to queue an SRCU callback. The child may be freed before that read.\nThe eventfs_mutex serializes list updates, but it does not keep the removed\nchild alive or prevent the SRCU callback from running.\n\nUse list_for_each_entry_safe() to save the next sibling before recursively\nremoving the current child."
    }
  ],
  "lastModified": "2026-08-25T06:18:37.160",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}