AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74400

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's BPF (Berkeley Packet Filter) functions, specifically `bpf_set_dentry_xattr` and `bpf_remove_dentry_xattr`, which can lead to a NULL pointer dereference when a negative dentry is provided. This flaw may result in a Denial of Service, particularly on systems with panic_on_warn enabled, as it can cause system crashes. Linux system administrators and developers utilizing BPF functionality should prioritize applying the fix to mitigate potential disruptions.

CVE
CVE-2026-74400
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries bpf_set_dentry_xattr and bpf_remove_dentry_xattr BPF kfuncs attempt to lock the inode of the supplied dentry without checking if it is NULL. If a negative dentry is passed (e.g. from security_inode_create), d_inode(dentry) returns NULL, and inode_lock(inode) will cause a NULL pointer dereference. Trivially fix this by adding a NULL check for inode before attempting to lock it, returning -EINVAL if it is NULL. Additionally, drop WARN_ON(!inode) in bpf_xattr_read_permission() and bpf_xattr_write_permission(). These warnings could be triggered by passing a negative dentry to bpf_get_dentry_xattr() or the _locked variants of the xattr kfuncs, potentially causing a Denial of Service on systems with panic_on_warn enabled. Instead, simply return -EINVAL.