CVE-2026-74330

Source
https://cve.org/CVERecord?id=CVE-2026-74330
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74330.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74330
Downstream
Published
2026-08-15T05:58:23.722Z
Modified
2026-08-16T03:48:34.907267869Z
Summary
configfs: fix lockless traversals of ->s_children
Details

In the Linux kernel, the following vulnerability has been resolved:

configfs: fix lockless traversals of ->s_children

Having the parent directory locked protects entries from removal by another thread, but it does not protect cursors from being moved around by lseek() - or freed, for that matter.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74330.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6f61076406251626be39651d114fac412b1e0c39
Fixed
77fd6f50f633a52c2db061e7d71d8cb486b0265e
Fixed
91f289728ec706b7ff1ca0ee845dd73ff2253488
Fixed
b166ab78dc3f48e83d2c80bdfde4159b31fdc5fb
Fixed
9e57e2863872e82e7c7237bc32299f67ebebc543
Fixed
459860529c109c5ce08b81c0776ca1200eaaeb4a
Fixed
637ef4961470e04455102b34ac484a34d8eca0a4
Fixed
e6d93108e0a27d7e6f95c7e45017d14ba2900d32
Fixed
9b9e8bb81c41fd27e7b57a1c936fde140548535f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74330.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.27
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74330.json"