CVE-2026-74359
CVE CVE-2026-74359EUVD EUVD-2026-59506Published 2026-08-15T05:58:43.000ZLast changed 2026-08-17T05:46:19.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: configfs_lookup(): don't leave ->s_dentry dangling on failure Normally ->s_dentry is cleared when dentry it's pointing to becomes negative (on eviction, realistically). However, that only happens if dentry gets to be positive in the first place; in case of inode allocation failure dentry never becomes positive, so ->d_iput() is not called at all. We do part of what normally would've been done by configfs_d_iput() (dropping the reference to configfs_dirent) manually, but we do not clear ->s_dentry there. Sloppy as it is, it does not matter in case of configfs_create_{dir,link}() - there configfs_dirent does not survive dropping the sole reference to it. However, for configfs_lookup() it *does* survive, with a dangling pointer to soon to be freed dentry sitting it its ->s_dentry. Subsequent getdents(2) in that directory will end up dereferencing that pointer in order to pick the inode number. Use after free... This is the minimal fix; the right approach is to set the linkage between dentry and configfs_dirent only after we know that we have an inode, but that takes more surgery and the bug had been there since 2006, so...
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <57088b06109f3222963c639d8d743f42c2899b13; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <eee07d769da5ac4e4f7bd0bc17828646a318d499; patch: 6.6.145; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <b6e9c82522ddaa3ac0706b295ff4a71975d4f883; patch: 6.18.40; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <3e83b2203aa59bd279e4f677ec793d49dc9d019e; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <10da12d352b7b2bb330a8609fdda9a58bf0e9856; patch: 5.15.212; patch: 0; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <9c747dcee164ead300de90550ad9e4122f0d1bbb; 3d0f89bb169482d26d5aa4e82e763077e7e9bc4d <c3b073a209a9baa691b744318ac929fecdd8847c; patch: 6.1.178; patch: 6.12.97; patch: 7.1.5; patch: 7.2; 2.6.16
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.