High severity7.8NVD Advisory· Published May 6, 2026· Updated Jun 1, 2026
CVE-2026-43074
CVE-2026-43074
Description
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: defer struct eventpoll free to RCU grace period
In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.4.1,<6.6.136
- cpe:2.3:o:linux:linux_kernel:6.4:-:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
7- git.kernel.org/stable/c/07712db80857d5d09ae08f3df85a708ecfc3b61fnvdPatch
- git.kernel.org/stable/c/5b1173b165421561db29f30afc7e97d940a398a9nvdPatch
- git.kernel.org/stable/c/7e8083f5eeedab0f460063b9c2c14c9a4e71a427nvdPatch
- git.kernel.org/stable/c/a6566cd33f6f967a7651ebf2ce0dd31572e319cfnvdPatch
- git.kernel.org/stable/c/ae0bb9c1fb7c2594519aeeb096cf2c3b7837b322nvdPatch
- git.kernel.org/stable/c/902120be4f44947df6311002addc7faf69bdbff1nvd
- git.kernel.org/stable/c/a6d57084372161f86660bc4607784420e00efe2cnvd
News mentions
0No linked articles in our index yet.