CVE-2026-74646

high

Description

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke When an invoke is interrupted by a signal, wait_for_completion_interruptible() returns -ERESTARTSYS and fastrpc_internal_invoke() moves every buffer from fl->mmaps onto cctx->invoke_interrupted_mmaps. This list_del()/list_add_tail() walk runs without holding fl->lock, the lock that serialises fl->mmaps in fastrpc_req_mmap() and fastrpc_req_munmap() everywhere else. Take fl->lock around the move, matching every other fl->mmaps accessor.

References

https://git.kernel.org/stable/c/efd02f8d1a7449f15809bc18d3cd41aafea75d7e

https://git.kernel.org/stable/c/b85a0e91d7d6cd06a53c881a46f749cfcef416a2

https://git.kernel.org/stable/c/af6345159abcbaa550518f31990d2a9558c2d369

https://git.kernel.org/stable/c/a902fe1f80f58a2335b6be1131866f827ec44d1a

https://git.kernel.org/stable/c/3f265e405e5ef85030c3777262e18bb556bc8724

Details

Source: Mitre, NVD

Published: 2026-08-22

Updated: 2026-08-22

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Severity: High

EPSS

EPSS: 0.00209