CVE-2026-43074: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.
Affected products
- Linux Linux Kernel: from 6.4.1, before 6.6.136 (fixed in 6.6.136); from 6.7, before 6.12.83 (fixed in 6.12.83); from 6.13, before 6.18.24 (fixed in 6.18.24); from 6.19, before 6.19.14 (fixed in 6.19.14); version 6.4 only; version 7.0 only
Published 2026-05-06. Last modified 2026-06-17.