Description
In the Linux kernel, the following vulnerability has been resolved:

eventfs: Fix use-after-free in eventfs_remove_rec()

eventfs_remove_rec() recursively removes the child at the current loop
position. After the recursive call returns, list_for_each_entry() advances
by reading list.next from the removed child.

If free_ei() drops the final reference, release_ei() reuses the list/rcu
union to queue an SRCU callback. The child may be freed before that read.
The eventfs_mutex serializes list updates, but it does not keep the removed
child alive or prevent the SRCU callback from running.

Use list_for_each_entry_safe() to save the next sibling before recursively
removing the current child.
Published: 2026-08-22
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A bug in the Linux kernel’s eventfs subsystem causes a use‑after‑free. The recursive removal of child entries in eventfs_remove_rec() can free an event data instance while a subsequent list traversal still accesses it. This flaw could allow an attacker to manipulate the eventfs filesystem and trigger a crash or arbitrary code execution within the kernel. The weakness is categorized as CWE‑416.

Affected Systems

The vulnerability affects systems running the Linux kernel when the eventfs filesystem is enabled. No specific kernel versions are listed, but the patch is included in all kernel releases after the commit that introduces the safe list traversal guard.

Risk and Exploitability

The CVSS score is not provided, yet CWE‑416 flaws are generally considered high‑severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely exploitation path requires local privileged access or the ability to create and manipulate eventfs entries. Once triggered, the kernel may crash or execute arbitrary code, compromising system confidentiality, integrity, and availability.

Generated by OpenCVE AI on August 22, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the eventfs_remove_rec() fix based on commit 5635211b44969f48.
  • Disable the eventfs filesystem if it is not needed, e.g., by ensuring it is not mounted or by removing the mount point.
  • If disabled builds are not an option, rebuild the kernel with CONFIG_EVENTFS disabled to eliminate the vulnerable code path.

Generated by OpenCVE AI on August 22, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Sat, 22 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix use-after-free in eventfs_remove_rec() eventfs_remove_rec() recursively removes the child at the current loop position. After the recursive call returns, list_for_each_entry() advances by reading list.next from the removed child. If free_ei() drops the final reference, release_ei() reuses the list/rcu union to queue an SRCU callback. The child may be freed before that read. The eventfs_mutex serializes list updates, but it does not keep the removed child alive or prevent the SRCU callback from running. Use list_for_each_entry_safe() to save the next sibling before recursively removing the current child.
Title eventfs: Fix use-after-free in eventfs_remove_rec()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-22T15:31:53.819Z

Reserved: 2026-08-15T05:44:03.920Z

Link: CVE-2026-74606

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T16:16:33.077

Modified: 2026-08-22T16:16:33.077

Link: CVE-2026-74606

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T18:00:04Z

Weaknesses