CVE-2026-74730
Last modified
CVE-2026-74730 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object for the duration of the FREE_STATEID so it doesn't get cleaned up from underneath us while operations are still in flight..
Description
In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call Dan Aloni reports that he was able to hit a use-after-free bug if a FREE_STATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfs_server' object for the duration of the FREE_STATEID so it doesn't get cleaned up from underneath us while operations are still in flight.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < ed2f92ce2fc48463c41e0e540b9a3454889e8af8; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < d858ab09e787106432d4d9830bad9dfedf02f890; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < af62f1af182d33a0de38308c012841885d8ab92e; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < ed1161ab6239761958b38d5667225634fc2be894; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < d71dfffa512e71b166a889484e4c3b148a9a3af2; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < 80ed3d762628b36c9e4b22fac7c65b72ef3b13dd; >= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009, < cf616096a0f3a2b60f7d68b6b39674a6867ded9c |
| Linux | Linux | 3.10 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74730?
How severe is CVE-2026-74730?
How do I fix CVE-2026-74730?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74725In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74726In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74727In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74728In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74729In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7473On affected platforms running Arista EOS where a tunnel deca…6.9
- CVE-2026-74731In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74732In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74733In the Linux kernel, the following vulnerability has been re…
- CVE-2026-7474HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vuln…8.8
- CVE-2026-7475The Sky Addons plugin for WordPress is vulnerable to Stored …6.4
- CVE-2026-74764Pandora contains a path traversal vulnerability in its TAR a…10
Are you affected by CVE-2026-74730?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
