cbcvebase.
CVE-2026-43074
published 2026-05-06

CVE-2026-43074: In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free()…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.48%
39.0th percentile
In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 58c9b016e12855286370dfb704c08498edbc857a < a6566cd33f6f967a7651ebf2ce0dd31572e319cfa6566cd33f6f967a7651ebf2ce0dd31572e319cf
linuxlinux>= 58c9b016e12855286370dfb704c08498edbc857a < 5b1173b165421561db29f30afc7e97d940a398a95b1173b165421561db29f30afc7e97d940a398a9
linuxlinux>= 58c9b016e12855286370dfb704c08498edbc857a < 7e8083f5eeedab0f460063b9c2c14c9a4e71a4277e8083f5eeedab0f460063b9c2c14c9a4e71a427
linuxlinux>= 58c9b016e12855286370dfb704c08498edbc857a < ae0bb9c1fb7c2594519aeeb096cf2c3b7837b322ae0bb9c1fb7c2594519aeeb096cf2c3b7837b322
linuxlinux>= 58c9b016e12855286370dfb704c08498edbc857a < 07712db80857d5d09ae08f3df85a708ecfc3b61f07712db80857d5d09ae08f3df85a708ecfc3b61f
linuxlinux>= a1f93804449d13f97dabd4b996817de4bf1ed67a < a6d57084372161f86660bc4607784420e00efe2ca6d57084372161f86660bc4607784420e00efe2c
linuxlinux>= f2451def095c1743adcfcb0cb5dadc86034e162a < 902120be4f44947df6311002addc7faf69bdbff1902120be4f44947df6311002addc7faf69bdbff1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.4.1 < 6.6.1366.6.136
linuxlinux_kernel>= 6.7 < 6.12.836.12.83
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
ubuntulinux-azure-6.8
ubuntulinux-azure-fde
ubuntulinux-azure-fde-5.15
ubuntulinux-azure-fde-6.8

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.