CVE-2026-74601

Source
https://cve.org/CVERecord?id=CVE-2026-74601
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74601.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74601
Downstream
Published
2026-08-22T15:31:50.092Z
Modified
2026-08-24T11:47:07.605845594Z
Summary
ring-buffer: Use current_context for safe per-CPU buffer swap
Details

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Use current_context for safe per-CPU buffer swap

The ringbufferswap_cpu() function currently checks the per-CPU committing counter to determine if a buffer is actively being written to before performing the swap. However, there exists a race window where this check can be bypassed:

ring_buffer_lock_reserve
    cpu_buffer = buffer->buffers[cpu];       // cpu_buffer_a
    rb_reserve_next_event
        rb_start_commit // inc committing
        if (unlikely(READ_ONCE(cpu_buffer->buffer) != buffer)) {...}
        __rb_reserve_next
            rb_move_tail
                rb_end_commit(cpu_buffer);   // dec committing => 0
                /* interrupt hits here, successfully swaps! */
                local_inc(&cpu_buffer->committing);

ring_buffer_unlock_commit
    cpu_buffer = buffer->buffers[cpu];      // cpu_buffer_b
    rb_commit
        rb_end_commit
        RB_WARN_ON(cpu_buffer, !local_read(&cpu_buffer->committing))
                                            // triggers warning

The committing counter can temporarily drop to 0 during a single write operation (within rbmovetail), creating a window where swap can succeed even though the write is still in progress. This leads to inconsistent buffer state and triggers the RBWARNON in rb_commit().

Replace the committing counter check with currentcontext checks, which are set at the entry of ringbufferlockreserve() and remain valid throughout the entire write operation, providing a reliable indicator of buffer busy state during swap.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74601.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4239c38fe0b3847e1e6d962c74b41b08ba0e2990
Fixed
26662bc8fced1d668fa1aa146eda085bfc67bd0b
Fixed
6b524e6b234e45c7f5f90d13b042c6f57f80105c
Fixed
597f279b7b4a06412e3d965e98cc36e181cdbede
Fixed
22709117d9ae95e52673685f98caac7c356a8227
Fixed
ad7e10c7ea89af45ac1bf1814855d45da472703d
Fixed
5b926fb04cb9ef3156dcf88c69a59d3d1a1c4f9f
Fixed
5e6e2a18c20e88167d414f666032792e8bf19b80
Fixed
f27bdc43077e4fcb5557dfc315ee8d91e741f483

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74601.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
5.10.266
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.217
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.184
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74601.json"