CVE-2026-74512 (GCVE-0-2026-74512)
Vulnerability from cvelistv5
Published
2026-08-15 12:27
Modified
2026-08-19 16:38
Summary
In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion. Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other rule removal helpers). This ensures that all existing RCU readers have exited the critical section before any underlying resources are destroyed.
Impacted products
Vendor Product Version
Linux Linux Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Version: 34d99af52ad40bd498ba66970579a5bc1fb1a3bc
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "kernel/auditfilter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "93616c567469510b7bba55b2674e0c4523fd7e64",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "3f82927b399d7a276c0c12b6ff4424b747a0c9a7",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "8ae135a8962be9d4e8a131eb18eb06cdf02a47ce",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "45bf3df5b32e5a49953e7ceabc55f7dd85380e46",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "cae0dfed5d307b240bff71c3cf206652d1b6f215",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "5b8f46864f06d6dbacb7dcea52bc084dfd122638",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            },
            {
              "lessThan": "246df90b5f1a8a6e6abbd2f058b029558720adec",
              "status": "affected",
              "version": "34d99af52ad40bd498ba66970579a5bc1fb1a3bc",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "kernel/auditfilter.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.3"
            },
            {
              "lessThan": "4.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.265",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.216",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.183",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.151",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.103",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.44",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.8",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "4.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix potential use-after-free in audit_del_rule()\n\n`audit_del_rule()` destroys `e-\u003erule.exe` via `audit_remove_mark_rule()`\nbefore unlinking the rule from RCU-visible filter lists and waiting for a\ngrace period. Concurrent readers in `audit_filter()` and\n`audit_filter_rules()` still dereference `e-\u003erule.exe`, while the fsnotify\nmark can be freed on an independent lifetime path. This creates a\nuse-after-free window during rule deletion.\n\nFix this by unlinking the rule from the RCU-visible lists and invoking\n`synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other\nrule removal helpers). This ensures that all existing RCU readers have\nexited the critical section before any underlying resources are destroyed."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - Reachable only via local NETLINK_AUDIT (AUDIT_DEL_RULE) or filesystem events that autoremove AUDIT_EXE rules; concurrent UAF readers run in syscall/io_uring exit audit filtering on the local host, not from remote network input.\nAC:L - The attacker controls both sides of the race by deleting an AUDIT_EXE rule (auditctl or deleting/moving the audited executable) while driving concurrent syscall/io_uring activity to keep RCU readers in audit_filter()/audit_filter_rules().\nPR:L - Besides CAP_AUDIT_CONTROL netlink deletion, unprivileged local users can trigger audit_del_rule() via fsnotify autoremove when deleting/moving an admin-configured audited executable they can write, without init-namespace root.\nUI:N - Exploitation requires no victim interaction; the attacker schedules rule deletion and concurrent audited syscalls/io_uring exits to hit the UAF window.\nS:U - Impact is kernel heap memory corruption and local privilege escalation within the host kernel security domain, not a documented cross-VM or IOMMU boundary escape.\nC:H - Use-after-free of audit_fsnotify_mark while audit_exe_compare()/audit_mark_compare() dereference mark-\u003eino/dev enables arbitrary kernel memory reads and info disclosure primitives.\nI:H - Freed fsnotify mark objects can be reallocated and corrupted to obtain arbitrary kernel writes, control-flow hijack, and local root code execution beyond audit rule deletion.\nA:H - Concurrent dereference of a freed audit_fsnotify_mark during audit filtering can immediately oops/panic the kernel; repeated triggering yields reliable denial of service."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-19T16:38:09.879Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/93616c567469510b7bba55b2674e0c4523fd7e64"
        },
        {
          "url": "https://git.kernel.org/stable/c/3f82927b399d7a276c0c12b6ff4424b747a0c9a7"
        },
        {
          "url": "https://git.kernel.org/stable/c/8ae135a8962be9d4e8a131eb18eb06cdf02a47ce"
        },
        {
          "url": "https://git.kernel.org/stable/c/45bf3df5b32e5a49953e7ceabc55f7dd85380e46"
        },
        {
          "url": "https://git.kernel.org/stable/c/78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf"
        },
        {
          "url": "https://git.kernel.org/stable/c/cae0dfed5d307b240bff71c3cf206652d1b6f215"
        },
        {
          "url": "https://git.kernel.org/stable/c/5b8f46864f06d6dbacb7dcea52bc084dfd122638"
        },
        {
          "url": "https://git.kernel.org/stable/c/246df90b5f1a8a6e6abbd2f058b029558720adec"
        }
      ],
      "title": "audit: fix potential use-after-free in audit_del_rule()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-74512",
    "datePublished": "2026-08-15T12:27:33.736Z",
    "dateReserved": "2026-08-15T05:44:03.909Z",
    "dateUpdated": "2026-08-19T16:38:09.879Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…