CVE-2026-74486
In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: use exe_file_deny_write_access() for the interpreter clone For MISC_FMT_OPEN_FILE entries load_misc_binary() clones the registered interpreter file and denies write access to the clone via plain deny_write_access(). The clone is installed as bprm->interpreter and later released by the exec machinery through exe_file_allow_write_access() which skips the i_writecount increment for files with FMODE_FSNOTIFY_HSM set. The deny and allow side can therefore come to different conclusions when pre-content watches are in play: if a pre-content watch is added to the interpreter after registration every subsequent exec through that entry takes a write denial on the clone that is never paired with a write allowance, driving the interpreter inode's i_writecount further down with each exec and leaving the interpreter unwritable even after the entry and all its users are gone. Take the write denial via exe_file_deny_write_access() so both sides of the pairing base their decision on the same file mode, and propagate failure instead of silently ignoring it: an interpreter that is concurrently open for writing now fails the exec with ETXTBSY, exactly like an interpreter freshly opened via open_exec() would.
Properties
- last_source
- FIRST EPSS
- epss_score
- 0.0022
- cve_id
- CVE-2026-74486
- signal_observed_at
- 2026-09-11T17:55:57+00:00
- retrieved_at
- 2026-10-09T03:34:45+00:00
- published_at
- 2026-08-15T13:17:53.497
- last_modified
- 2026-08-23T13:16:44.640
- epss_percentile
- 0.11429
Related Entities (2)
ENRICHED_BY (1)
DESCRIBED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph