CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081543-CVE-2026-74512-3449@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion. Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other rule removal helpers). This ensures that all existing RCU readers have exited the critical section before any underlying resources are destroyed. The Linux kernel CVE team has assigned CVE-2026-74512 to this issue. Affected and fixed versions =========================== Issue introduced in 4.3 with commit 34d99af52ad40bd498ba66970579a5bc1fb1a3bc and fixed in 6.6.151 with commit 45bf3df5b32e5a49953e7ceabc55f7dd85380e46 Issue introduced in 4.3 with commit 34d99af52ad40bd498ba66970579a5bc1fb1a3bc and fixed in 6.12.103 with commit 78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf Issue introduced in 4.3 with commit 34d99af52ad40bd498ba66970579a5bc1fb1a3bc and fixed in 6.18.44 with commit cae0dfed5d307b240bff71c3cf206652d1b6f215 Issue introduced in 4.3 with commit 34d99af52ad40bd498ba66970579a5bc1fb1a3bc and fixed in 7.1.8 with commit 5b8f46864f06d6dbacb7dcea52bc084dfd122638 Issue introduced in 4.3 with commit 34d99af52ad40bd498ba66970579a5bc1fb1a3bc and fixed in 7.2-rc6 with commit 246df90b5f1a8a6e6abbd2f058b029558720adec Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74512 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/auditfilter.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/45bf3df5b32e5a49953e7ceabc55f7dd85380e46 https://git.kernel.org/stable/c/78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf https://git.kernel.org/stable/c/cae0dfed5d307b240bff71c3cf206652d1b6f215 https://git.kernel.org/stable/c/5b8f46864f06d6dbacb7dcea52bc084dfd122638 https://git.kernel.org/stable/c/246df90b5f1a8a6e6abbd2f058b029558720adec