CVE-2026-74590
Last modified
CVE-2026-74590 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the memory space referenced by a dynptr remains valid. They do not, however, provide any guarantee that the contents of the memory are stable.
Description
In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the memory space referenced by a dynptr remains valid. They do not, however, provide any guarantee that the contents of the memory are stable. kfuncs are expected to remain memory-safe even if concurrent modifications occur. bpf_get_fsverity_digest() didn't follow that: it could crash if arg->digest_size was concurrently modified. Fix that by using the known-good value hash_alg->digest_size instead. Also widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return type of __bpf_dynptr_size(). It doesn't appear that it can actually be more than INT_MAX currently (since __bpf_dynptr_data_rw() excludes file-based pointers), but the correct type might as well be used.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 67814c00de3161181cddd06c77aeaf86ac4cc584, < 1344b632cb5043e32939a84568125719111c5af3; >= 67814c00de3161181cddd06c77aeaf86ac4cc584, < 2a5cfcad1d56e26d645b7887b0ed24c371851525; >= 67814c00de3161181cddd06c77aeaf86ac4cc584, < 5bd63cad9df4328a184c409fbdad4f17944bcdb8; >= 67814c00de3161181cddd06c77aeaf86ac4cc584, < 3e8ec7c0387273329374f5c7bd61f5f38af71fe1 |
| Linux | Linux | 6.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74590?
How severe is CVE-2026-74590?
How do I fix CVE-2026-74590?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74585In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74586In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74587In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74588In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74589In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7459The Simple History – Track, Log, and Audit WordPress Changes…7.5
- CVE-2026-74591In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74592In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74593In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74594In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74595In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74596In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-74590?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
