CVE-2026-74512
In the Linux kernel, the following vulnerability has been resolved:
audit: fix potential use-after-free in audit_del_rule()
audit_del_rule() destroys e->rule.exe via audit_remove_mark_rule()
before unlinking the rule from RCU-visible filter lists and waiting for a
grace period. Concurrent readers in audit_filter() and
audit_filter_rules() still dereference e->rule.exe, while the fsnotify
mark can be freed on an independent lifetime path. This creates a
use-after-free window during rule deletion.
Fix this by unlinking the rule from the RCU-visible lists and invoking
synchronize_rcu() before calling audit_remove_mark_rule() (and other
rule removal helpers). This ensures that all existing RCU readers have
exited the critical section before any underlying resources are destroyed.
⚡ Watch CVE-2026-74512
Get an email if CVE-2026-74512 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-74512)