PatchSiren cyber security CVE debrief
CVE-2026-43074 Linux CVE debrief
CVE-2026-43074 is a Linux kernel eventpoll use-after-free in ep_free() where struct eventpoll can be freed while another concurrent thread is still using it. The fix defers the kfree() to an RCU callback to avoid the race. NVD rates the issue HIGH with CVSS 7.8.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-06
- Original CVE updated
- 2026-06-01
- Advisory published
- 2026-05-06
- Advisory updated
- 2026-06-01
Who should care
Linux kernel maintainers, distro security teams, embedded/device OEMs, and operators of systems that allow local user workloads should prioritize this advisory. Because the CVSS vector is local and requires low privileges, multi-user servers, container hosts, and developer workstations may be more exposed to practical abuse than single-user appliances.
Technical summary
The vulnerability is a race in eventpoll.c: ep_free() could kfree the epi->ep eventpoll structure before all concurrent readers were finished with it, creating a use-after-free condition. The published fix changes cleanup to an RCU-deferred free so the memory is not released until after an RCU grace period. NVD maps the issue to CWE-401 and assigns CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Affected version ranges in NVD include Linux kernel 6.4.1 through before 6.6.136, 6.7 through before 6.12.83, 6.13 through before 6.18.24, and 6.19 through before 6.19.14, with additional vulnerable 6.4 and 7.0-rc builds listed in the record.
Defensive priority
High. The vulnerability is local and requires low privileges, but the impact is complete confidentiality, integrity, and availability compromise per CVSS. Systems with untrusted local users, shared hosts, or containerized workloads should be patched promptly.
Recommended defensive actions
- Apply the relevant Linux kernel stable update that includes the eventpoll RCU-free fix.
- Verify vendor backports for your distribution or embedded kernel before assuming a version string is safe.
- Prioritize patching multi-user systems, developer workstations, and hosts that run untrusted local workloads.
- Confirm whether your fleet falls within the NVD-identified affected kernel version ranges and release candidates.
- Track the linked kernel patch references for the exact backported commit applied by your vendor.
Evidence notes
This debrief is based only on the supplied NVD CVE record and the linked official kernel patch references. The vulnerability description states that ep_free() could free struct eventpoll while still in use, and that the remediation defers kfree() to an RCU callback. Timing context uses the provided CVE publishedAt (2026-05-06T10:16:20.343Z) and modifiedAt (2026-05-20T23:20:05.510Z) fields; no KEV entry was provided.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43074 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43074
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43074 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43074
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/07712db80857d5d09ae08f3df85a708ecfc3b61f
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/5b1173b165421561db29f30afc7e97d940a398a9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/7e8083f5eeedab0f460063b9c2c14c9a4e71a427
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a6566cd33f6f967a7651ebf2ce0dd31572e319cf
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ae0bb9c1fb7c2594519aeeb096cf2c3b7837b322
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.