PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43074 Linux CVE debrief

CVE-2026-43074 is a Linux kernel eventpoll use-after-free in ep_free() where struct eventpoll can be freed while another concurrent thread is still using it. The fix defers the kfree() to an RCU callback to avoid the race. NVD rates the issue HIGH with CVSS 7.8.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-06
Original CVE updated
2026-06-01
Advisory published
2026-05-06
Advisory updated
2026-06-01

Who should care

Linux kernel maintainers, distro security teams, embedded/device OEMs, and operators of systems that allow local user workloads should prioritize this advisory. Because the CVSS vector is local and requires low privileges, multi-user servers, container hosts, and developer workstations may be more exposed to practical abuse than single-user appliances.

Technical summary

The vulnerability is a race in eventpoll.c: ep_free() could kfree the epi->ep eventpoll structure before all concurrent readers were finished with it, creating a use-after-free condition. The published fix changes cleanup to an RCU-deferred free so the memory is not released until after an RCU grace period. NVD maps the issue to CWE-401 and assigns CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Affected version ranges in NVD include Linux kernel 6.4.1 through before 6.6.136, 6.7 through before 6.12.83, 6.13 through before 6.18.24, and 6.19 through before 6.19.14, with additional vulnerable 6.4 and 7.0-rc builds listed in the record.

Defensive priority

High. The vulnerability is local and requires low privileges, but the impact is complete confidentiality, integrity, and availability compromise per CVSS. Systems with untrusted local users, shared hosts, or containerized workloads should be patched promptly.

Recommended defensive actions

  • Apply the relevant Linux kernel stable update that includes the eventpoll RCU-free fix.
  • Verify vendor backports for your distribution or embedded kernel before assuming a version string is safe.
  • Prioritize patching multi-user systems, developer workstations, and hosts that run untrusted local workloads.
  • Confirm whether your fleet falls within the NVD-identified affected kernel version ranges and release candidates.
  • Track the linked kernel patch references for the exact backported commit applied by your vendor.

Evidence notes

This debrief is based only on the supplied NVD CVE record and the linked official kernel patch references. The vulnerability description states that ep_free() could free struct eventpoll while still in use, and that the remediation defers kfree() to an RCU callback. Timing context uses the provided CVE publishedAt (2026-05-06T10:16:20.343Z) and modifiedAt (2026-05-20T23:20:05.510Z) fields; no KEV entry was provided.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43074 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43074

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43074 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43074

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/07712db80857d5d09ae08f3df85a708ecfc3b61f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/5b1173b165421561db29f30afc7e97d940a398a9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/7e8083f5eeedab0f460063b9c2c14c9a4e71a427

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a6566cd33f6f967a7651ebf2ce0dd31572e319cf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ae0bb9c1fb7c2594519aeeb096cf2c3b7837b322

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.