Sploitus

CVE-2026-74512

No indexed exploits for CVE-2026-74512 yet

In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion. Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_rcu()` before calling `audit_remove_mark_rule()` (and other rule removal helpers). This ensures that all existing RCU readers have exited the critical section before any underlying resources are destroyed.

Affected products
Linux Kernel
CVSS 3.1
7.8 HIGH
EPSS
0.1% (2th percentile)
NVD status
Received
Published
2026-08-15
CVE-2026-74512 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-74512 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-74512 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.