-

CVE-2026-74486

binfmt_misc: use exe_file_deny_write_access() for the interpreter clone

In the Linux kernel, the following vulnerability has been resolved:

binfmt_misc: use exe_file_deny_write_access() for the interpreter clone

For MISC_FMT_OPEN_FILE entries load_misc_binary() clones the
registered interpreter file and denies write access to the clone via
plain deny_write_access(). The clone is installed as
bprm->interpreter and later released by the exec machinery through
exe_file_allow_write_access() which skips the i_writecount increment
for files with FMODE_FSNOTIFY_HSM set.

The deny and allow side can therefore come to different conclusions
when pre-content watches are in play: if a pre-content watch is added
to the interpreter after registration every subsequent exec through
that entry takes a write denial on the clone that is never paired
with a write allowance, driving the interpreter inode's i_writecount
further down with each exec and leaving the interpreter unwritable
even after the entry and all its users are gone.

Take the write denial via exe_file_deny_write_access() so both sides
of the pairing base their decision on the same file mode, and
propagate failure instead of silently ignoring it: an interpreter
that is concurrently open for writing now fails the exec with
ETXTBSY, exactly like an interpreter freshly opened via open_exec()
would.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 5b432413f7bbbc8b935138490a57be05c1921684
Version < c65eb018c12179b5e2c7afe1f0956298576fecec
Status affected
Version bb4715098d8e340bbbdd3a874b31f89867c8067e
Version < 2bd860b7e752a51185960143cab9fec7bf32c84e
Status affected
Version c152be5adc0975c75cc4f50891c9072d52d60b47
Version < eea4b7c7711b1e425272d23352af157f45f4c3e3
Status affected
Version bf5ed2ef5cdb7b47ce606e3d48ea6eb803b31503
Version < 2fdf8b07bee5ef99ec77773a6be05fbb8ee5cdb9
Status affected
Version 483217fd6f7ccd98b3ed2531a54f75ed144b4499
Version < f1e7ea3c8e070f19771cdaef55bbeda1359ad490
Status affected
Version 0357ef03c94ef835bd44a0658b8edb672a9dbf51
Version < 255a758697da87a205e072e0cfc35897b8f743b1
Status affected
Version 0357ef03c94ef835bd44a0658b8edb672a9dbf51
Version < f0edbaf487e4653a680a7abb91c1df94cb7886aa
Status affected
Version 0357ef03c94ef835bd44a0658b8edb672a9dbf51
Version < fa5990ca8fd917003e526036bcc50413edb9722c
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.14
Status affected
Version 0
Version < 6.14
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.063
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/255a758697da87a205e072e0cfc35897b8f743b1
https://git.kernel.org/stable/c/f0edbaf487e4653a680a7abb91c1df94cb7886aa
https://git.kernel.org/stable/c/fa5990ca8fd917003e526036bcc50413edb9722c
https://git.kernel.org/stable/c/2bd860b7e752a51185960143cab9fec7bf32c84e
https://git.kernel.org/stable/c/2fdf8b07bee5ef99ec77773a6be05fbb8ee5cdb9
https://git.kernel.org/stable/c/c65eb018c12179b5e2c7afe1f0956298576fecec
https://git.kernel.org/stable/c/eea4b7c7711b1e425272d23352af157f45f4c3e3
https://git.kernel.org/stable/c/f1e7ea3c8e070f19771cdaef55bbeda1359ad490