CVE-2026-74486

Source
https://cve.org/CVERecord?id=CVE-2026-74486
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74486.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74486
Downstream
Published
2026-08-15T12:27:17Z
Modified
2026-08-25T03:51:25Z
Summary
binfmt_misc: use exe_file_deny_write_access() for the interpreter clone
Details

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: use exe_file_deny_write_access() for the interpreter clone

For MISC_FMT_OPEN_FILE entries load_misc_binary() clones the registered interpreter file and denies write access to the clone via plain deny_write_access(). The clone is installed as bprm->interpreter and later released by the exec machinery through exe_file_allow_write_access() which skips the i_writecount increment for files with FMODE_FSNOTIFY_HSM set.

The deny and allow side can therefore come to different conclusions when pre-content watches are in play: if a pre-content watch is added to the interpreter after registration every subsequent exec through that entry takes a write denial on the clone that is never paired with a write allowance, driving the interpreter inode's i_writecount further down with each exec and leaving the interpreter unwritable even after the entry and all its users are gone.

Take the write denial via exe_file_deny_write_access() so both sides of the pairing base their decision on the same file mode, and propagate failure instead of silently ignoring it: an interpreter that is concurrently open for writing now fails the exec with ETXTBSY, exactly like an interpreter freshly opened via open_exec() would.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74486.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b432413f7bbbc8b935138490a57be05c1921684
Fixed
c65eb018c12179b5e2c7afe1f0956298576fecec
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bb4715098d8e340bbbdd3a874b31f89867c8067e
Fixed
2bd860b7e752a51185960143cab9fec7bf32c84e
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c152be5adc0975c75cc4f50891c9072d52d60b47
Fixed
eea4b7c7711b1e425272d23352af157f45f4c3e3
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf5ed2ef5cdb7b47ce606e3d48ea6eb803b31503
Fixed
2fdf8b07bee5ef99ec77773a6be05fbb8ee5cdb9
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
483217fd6f7ccd98b3ed2531a54f75ed144b4499
Fixed
f1e7ea3c8e070f19771cdaef55bbeda1359ad490
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0357ef03c94ef835bd44a0658b8edb672a9dbf51
Fixed
255a758697da87a205e072e0cfc35897b8f743b1
Fixed
f0edbaf487e4653a680a7abb91c1df94cb7886aa
Fixed
fa5990ca8fd917003e526036bcc50413edb9722c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74486.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.18.44
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74486.json"