CVE-2026-74730

Source
https://cve.org/CVERecord?id=CVE-2026-74730
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74730.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74730
Downstream
Published
2026-08-22T15:33:19.659Z
Modified
2026-08-24T11:45:53.869327172Z
Summary
NFS: Pin the 'struct nfs_server' during a FREE_STATEID call
Details

In the Linux kernel, the following vulnerability has been resolved:

NFS: Pin the 'struct nfsserver' during a FREESTATEID call

Dan Aloni reports that he was able to hit a use-after-free bug if a FREESTATEID operation gets delayed for whatever reason. Fix this by bumping the refcount of the 'struct nfsserver' object for the duration of the FREE_STATEID so it doesn't get cleaned up from underneath us while operations are still in flight.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74730.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009
Fixed
ed2f92ce2fc48463c41e0e540b9a3454889e8af8
Fixed
d858ab09e787106432d4d9830bad9dfedf02f890
Fixed
af62f1af182d33a0de38308c012841885d8ab92e
Fixed
caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd
Fixed
ed1161ab6239761958b38d5667225634fc2be894
Fixed
d71dfffa512e71b166a889484e4c3b148a9a3af2
Fixed
80ed3d762628b36c9e4b22fac7c65b72ef3b13dd
Fixed
cf616096a0f3a2b60f7d68b6b39674a6867ded9c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74730.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.10.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74730.json"