Description
In the Linux kernel, the following vulnerability has been resolved:

fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions

The BPF verifier and the dynptr abstraction ensure that the memory space
referenced by a dynptr remains valid. They do not, however, provide any
guarantee that the contents of the memory are stable. kfuncs are
expected to remain memory-safe even if concurrent modifications occur.

bpf_get_fsverity_digest() didn't follow that: it could crash if
arg->digest_size was concurrently modified.

Fix that by using the known-good value hash_alg->digest_size instead.

Also widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return
type of __bpf_dynptr_size(). It doesn't appear that it can actually be
more than INT_MAX currently (since __bpf_dynptr_data_rw() excludes
file-based pointers), but the correct type might as well be used.
Published: 2026-08-22
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the bpf_get_fsverity_digest helper suffers from a race condition that leads to kernel crashes. This flaw is a CWE-663 weakness, where the implementation incorrectly assumes that the contents of a dynptr are stable during concurrent modifications. An attacker can craft a BPF program that invokes the helper, causing the kernel to read a corrupted digest size and ultimately leading to a denial of service.

Affected Systems

All releases of the Linux kernel that include the buggy bpf_get_fsverity_digest implementation before the patch commit are affected. The advisory does not list specific kernel versions, but any kernel version released prior to the inclusion of the fix may be vulnerable. The flaw resides in the core Linux kernel.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating no widespread exploitation yet. The CVSS score of 7.8 reflects a high severity. The likely attack vector is a local user who can load a BPF program that invokes the helper, implying a privilege or trusted user context rather than remote exploitation. In environments where arbitrary BPF programs are permitted, exploitation can trigger a kernel crash, causing a denial of service.

Generated by OpenCVE AI on August 25, 2026 at 18:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch for CVE-2026-74590.
  • Restrict BPF program loading by enforcing strict capability checks or applying LSM restrictions to limit the execution of BPF code to trusted users only.
  • Implement monitoring of kernel panics and BPF program activity to detect and respond to potential exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 18:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-663
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Tue, 25 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-847

Tue, 25 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 22 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-847

Sat, 22 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions The BPF verifier and the dynptr abstraction ensure that the memory space referenced by a dynptr remains valid. They do not, however, provide any guarantee that the contents of the memory are stable. kfuncs are expected to remain memory-safe even if concurrent modifications occur. bpf_get_fsverity_digest() didn't follow that: it could crash if arg->digest_size was concurrently modified. Fix that by using the known-good value hash_alg->digest_size instead. Also widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return type of __bpf_dynptr_size(). It doesn't appear that it can actually be more than INT_MAX currently (since __bpf_dynptr_data_rw() excludes file-based pointers), but the correct type might as well be used.
Title fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-25T05:40:17.568Z

Reserved: 2026-08-15T05:44:03.918Z

Link: CVE-2026-74590

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T16:16:31.243

Modified: 2026-08-25T06:18:34.113

Link: CVE-2026-74590

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-22T00:00:00Z

Links: CVE-2026-74590 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T19:00:08Z

Weaknesses
  • CWE-663

    Use of a Non-reentrant Function in a Concurrent Context