CVE-2026-74646

Unknown

Last modified

CVE-2026-74646 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke When an invoke is interrupted by a signal, wait_for_completion_interruptible() returns -ERESTARTSYS and fastrpc_internal_invoke() moves every buffer from fl->mmaps onto cctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk runs without holding fl->lock, the lock that serialises fl->mmaps in fastrpc_req_mmap() and fastrpc_req_munmap() everywhere else. Take fl->lock around the move, matching every other fl->mmaps accessor..

Description

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke When an invoke is interrupted by a signal, wait_for_completion_interruptible() returns -ERESTARTSYS and fastrpc_internal_invoke() moves every buffer from fl->mmaps onto cctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk runs without holding fl->lock, the lock that serialises fl->mmaps in fastrpc_req_mmap() and fastrpc_req_munmap() everywhere else. Take fl->lock around the move, matching every other fl->mmaps accessor.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 76e8e4ace1ed2c97dba3b1370e0e105e07c572bc, < 3f265e405e5ef85030c3777262e18bb556bc8724; >= 76e8e4ace1ed2c97dba3b1370e0e105e07c572bc, < a902fe1f80f58a2335b6be1131866f827ec44d1a; >= 76e8e4ace1ed2c97dba3b1370e0e105e07c572bc, < af6345159abcbaa550518f31990d2a9558c2d369; >= 76e8e4ace1ed2c97dba3b1370e0e105e07c572bc, < efd02f8d1a7449f15809bc18d3cd41aafea75d7e; >= 76e8e4ace1ed2c97dba3b1370e0e105e07c572bc, < b85a0e91d7d6cd06a53c881a46f749cfcef416a2
LinuxLinux6.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74646?
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke When an invoke is interrupted by a signal, wait_for_completion_interruptible() returns -ERESTARTSYS and fastrpc_internal_invoke() moves every buffer from fl->mmaps onto cctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk runs without holding fl->lock, the lock that serialises fl->mmaps in fastrpc_req_mmap() and fastrpc_req_munmap() everywhere else. Take fl->lock around the move, matching every other fl->mmaps accessor.
How severe is CVE-2026-74646?
Severity scoring for CVE-2026-74646 is pending analysis.
How do I fix CVE-2026-74646?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74646?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST