binfmt_misc: restore write access when removing an entry
Summary
| CVE | CVE-2026-74487 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 13:17:53 UTC |
| Updated | 2026-08-15 13:17:53 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
binfmt_misc: restore write access when removing an entry
Registering an entry with the MISC_FMT_OPEN_FILE flag opens the
interpreter via open_exec() which denies write access to it for as
long as the entry exists. Removing the entry closes the interpreter
file via filp_close() but never restores write access, leaving the
inode's i_writecount permanently negative. Opening the interpreter
for writing keeps failing with ETXTBSY long after the entry is gone
until the inode is evicted from the inode cache.
Commit 90f601b497d7 ("binfmt_misc: restore write access before
closing files opened by open_exec()") fixed the same imbalance in the
error path of bm_register_write() but the actual removal path has
been leaking the write denial since the introduction of the flag.
Restore write access in put_binfmt_handler() before closing the
interpreter file. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 948b701a607f123df92ed29084413e5dd8cda2ed fdc1d702bf3001586221fa07e598e876a0a854c5 git |
Not specified |
| CNA |
Linux |
Linux |
affected 948b701a607f123df92ed29084413e5dd8cda2ed 3b522487a3a9162b1b519eefde7998d103e3e07b git |
Not specified |
| CNA |
Linux |
Linux |
affected 948b701a607f123df92ed29084413e5dd8cda2ed db1856ea9196cf6e015d12199a34c0b9313c7bfa git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.8 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.8 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.44 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.8 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc6 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/db1856ea9196cf6e015d12199a34c0b9313c7bfa |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fdc1d702bf3001586221fa07e598e876a0a854c5 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3b522487a3a9162b1b519eefde7998d103e3e07b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.