CVE-2026-74363
Last modified
CVE-2026-74363 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs commit 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning htab with internal structs") moved inode cleanup from ->free_inode() into ->destroy_inode() to avoid sleeping in RCU context when calling bpf_any_put(). However this removed the RCU delay on freeing the inode itself and the cached symlink body (i_link), both of which can be accessed by RCU pathwalk (pick_link, may_lookup etc.). This causes a use-after-free when a concurrent unlinkat() drops the last inode reference and destroy_inode() frees the inode immediately, while another task is still walking the path in RCU mode and reads inode->i_opflags (offset +2) inside current_time() -> is_mgtime(). KASAN reports: BUG: KASAN: slab-use-after-free in is_mgtime include/linux/fs.h:2313 Read of size 2 at addr ffff8880407e4282 (offset +2 = i_opflags) The rules (per Al Viro): ->destroy_inode() called immediately, can sleep, use for blocking cleanup e.g. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs commit 4f375ade6aa9 ("bpf: Avoid RCU context warning when unpinning htab with internal structs") moved inode cleanup from ->free_inode() into ->destroy_inode() to avoid sleeping in RCU context when calling bpf_any_put(). However this removed the RCU delay on freeing the inode itself and the cached symlink body (i_link), both of which can be accessed by RCU pathwalk (pick_link, may_lookup etc.). This causes a use-after-free when a concurrent unlinkat() drops the last inode reference and destroy_inode() frees the inode immediately, while another task is still walking the path in RCU mode and reads inode->i_opflags (offset +2) inside current_time() -> is_mgtime(). KASAN reports: BUG: KASAN: slab-use-after-free in is_mgtime include/linux/fs.h:2313 Read of size 2 at addr ffff8880407e4282 (offset +2 = i_opflags) The rules (per Al Viro): ->destroy_inode() called immediately, can sleep, use for blocking cleanup e.g. bpf_any_put() ->free_inode() called after RCU grace period, use for freeing inode and anything RCU-accessible e.g. i_link Fix: split the two concerns properly: - keep bpf_any_put() in bpf_destroy_inode() since it is blocking and needs to run promptly - introduce bpf_free_inode() to handle kfree(i_link) and free_inode_nonrcu() with proper RCU delay, preventing the UAF
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= e28616ca3d67e745ecb2f10eba4a626e1fc9a203, < ea1c243c39e32b7fc1c2edfe32081ff7e30a877c; >= 743a620c661994c7f0938e6dd32fb0883fb1e0ea, < 5fecb71c10c28aef276ba49c718dc961745fdcf0; >= b6e9645be9eb93f7aff3ca887f8edb6f1d63358f, < c70d0f9114c3cc156f6029a400c4eb7e6f7c82b2; >= ee04cff9ed4d6bb25802f5cecfcd0750500410f3, < 53649846e0437d1d9b7cb993cfe54c367addf7ae; >= 4f375ade6aa9f37fd72d7a78682f639772089eed, < 61f19729728243c82476dee31315143ed3275e7f; >= 4f375ade6aa9f37fd72d7a78682f639772089eed, < 0497ff765746d9b2d17445c8f7cc737b36c0152a; >= 4f375ade6aa9f37fd72d7a78682f639772089eed, < b93c55b4932dd7e32dca8cf34a3443cc87a02906; de2d2baecc84cc7fca52eec2b9b55d89c93e3565; >= 5.15.195, < 5.15.212; >= 6.1.157, < 6.1.178; >= 6.6.113, < 6.6.145; >= 6.12.54, < 6.12.97; >= 6.17.4, < 6.18 |
| Linux | Linux | 6.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74363?
How severe is CVE-2026-74363?
How do I fix CVE-2026-74363?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74358In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74359In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-7436The WPC Badge Management for WooCommerce plugin for WordPres…6.4
- CVE-2026-74360In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74361In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-74362In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74364In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-74365In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-74366In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74367In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74368In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74369In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
