CVE-2026-74487
Last modified
CVE-2026-74487 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access when removing an entry Registering an entry with the MISC_FMT_OPEN_FILE flag opens the interpreter via open_exec() which denies write access to it for as long as the entry exists. Removing the entry closes the interpreter file via filp_close() but never restores write access, leaving the inode's i_writecount permanently negative. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access when removing an entry Registering an entry with the MISC_FMT_OPEN_FILE flag opens the interpreter via open_exec() which denies write access to it for as long as the entry exists. Removing the entry closes the interpreter file via filp_close() but never restores write access, leaving the inode's i_writecount permanently negative. Opening the interpreter for writing keeps failing with ETXTBSY long after the entry is gone until the inode is evicted from the inode cache. Commit 90f601b497d7 ("binfmt_misc: restore write access before closing files opened by open_exec()") fixed the same imbalance in the error path of bm_register_write() but the actual removal path has been leaking the write denial since the introduction of the flag. Restore write access in put_binfmt_handler() before closing the interpreter file.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 948b701a607f123df92ed29084413e5dd8cda2ed, < 7873f987213695e3564c8c259e6db283e4739472; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < 13efc628fdf641d901bdba07caa1c558e1bed046; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < f1cf67f6be0babc73afa4ee0e27bdedffeeeb095; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < dd9ba32169e73a3c3ba595cf1de1f4c69ceafb3c; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < a50296cca2a1db9d8d21051e7d50f0cf3a4b7ec8; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < fdc1d702bf3001586221fa07e598e876a0a854c5; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < 3b522487a3a9162b1b519eefde7998d103e3e07b; >= 948b701a607f123df92ed29084413e5dd8cda2ed, < db1856ea9196cf6e015d12199a34c0b9313c7bfa |
| Linux | Linux | 4.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74487?
How severe is CVE-2026-74487?
How do I fix CVE-2026-74487?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74481In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74482In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74483In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74484In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74485In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-74486In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74488In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-74489In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-74490In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-74491In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74492In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-74493In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2026-74487?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
