ReviewHigh

CVE-2026-74512

Linux

In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion. Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.15
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: audit: fix potential use-after-free in audit_del_rule() `audit_del_rule()` destroys `e->rule.exe` via `audit_remove_mark_rule()` before unlinking the rule from RCU-visible filter lists and waiting for a grace period. Concurrent readers in `audit_filter()` and `audit_filter_rules()` still dereference `e->rule.exe`, while the fsnotify mark can be freed on an independent lifetime path. This creates a use-after-free window during rule deletion. Fix this by unlinking the rule from the RCU-visible lists and invoking `synchronize_...

Affected product and versions

Product
Linux
Affected versions
>= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 93616c567469510b7bba55b2674e0c4523fd7e64, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 3f82927b399d7a276c0c12b6ff4424b747a0c9a7, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 8ae135a8962be9d4e8a131eb18eb06cdf02a47ce, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 45bf3df5b32e5a49953e7ceabc55f7dd85380e46, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 78bde7e9bd36eaae1b8e8cfcd47f12a34f301dbf, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < cae0dfed5d307b240bff71c3cf206652d1b6f215, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 5b8f46864f06d6dbacb7dcea52bc084dfd122638, >= 34d99af52ad40bd498ba66970579a5bc1fb1a3bc < 246df90b5f1a8a6e6abbd2f058b029558720adec, >= 4.3
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available