Bug 2483519 (CVE-2026-46242) - CVE-2026-46242 kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF
Summary: CVE-2026-46242 kernel: eventpoll: fix ep_remove struct eventpoll / struct fil...
Keywords:
Status: NEW
Alias: CVE-2026-46242
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-30 13:01 UTC by OSIDB Bzimport
Modified: 2026-07-21 15:20 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:36186 0 None None None 2026-07-07 09:36:28 UTC
Red Hat Product Errata RHSA-2026:36541 0 None None None 2026-07-08 05:05:03 UTC
Red Hat Product Errata RHSA-2026:36645 0 None None None 2026-07-08 11:36:31 UTC
Red Hat Product Errata RHSA-2026:37729 0 None None None 2026-07-10 12:51:54 UTC
Red Hat Product Errata RHSA-2026:38902 0 None None None 2026-07-13 12:50:47 UTC
Red Hat Product Errata RHSA-2026:39371 0 None None None 2026-07-14 16:41:22 UTC
Red Hat Product Errata RHSA-2026:40764 0 None None None 2026-07-21 15:13:29 UTC
Red Hat Product Errata RHSA-2026:40779 0 None None None 2026-07-21 15:20:23 UTC
Red Hat Product Errata RHSA-2026:40787 0 None None None 2026-07-21 15:20:34 UTC

Description OSIDB Bzimport 2026-05-30 13:01:15 UTC
In the Linux kernel, the following vulnerability has been resolved:

eventpoll: fix ep_remove struct eventpoll / struct file UAF

ep_remove() (via ep_remove_file()) cleared file->f_ep under
file->f_lock but then kept using @file inside the critical section
(is_file_epoll(), hlist_del_rcu() through the head, spin_unlock).
A concurrent __fput() taking the eventpoll_release() fastpath in
that window observed the transient NULL, skipped
eventpoll_release_file() and ran to f_op->release / file_free().

For the epoll-watches-epoll case, f_op->release is
ep_eventpoll_release() -> ep_clear_and_put() -> ep_free(), which
kfree()s the watched struct eventpoll. Its embedded ->refs
hlist_head is exactly where epi->fllink.pprev points, so the
subsequent hlist_del_rcu()'s "*pprev = next" scribbles into freed
kmalloc-192 memory.

In addition, struct file is SLAB_TYPESAFE_BY_RCU, so the slot
backing @file could be recycled by alloc_empty_file() --
reinitializing f_lock and f_ep -- while ep_remove() is still
nominally inside that lock. The upshot is an attacker-controllable
kmem_cache_free() against the wrong slab cache.

Pin @file via epi_fget() at the top of ep_remove() and gate the
critical section on the pin succeeding. With the pin held @file
cannot reach refcount zero, which holds __fput() off and
transitively keeps the watched struct eventpoll alive across the
hlist_del_rcu() and the f_lock use, closing both UAFs.

If the pin fails @file has already reached refcount zero and its
__fput() is in flight. Because we bailed before clearing f_ep,
that path takes the eventpoll_release() slow path into
eventpoll_release_file() and blocks on ep->mtx until the waiter
side's ep_clear_and_put() drops it. The bailed epi's share of
ep->refcount stays intact, so the trailing ep_refcount_dec_and_test()
in ep_clear_and_put() cannot free the eventpoll out from under
eventpoll_release_file(); the orphaned epi is then cleaned up
there.

A successful pin also proves we are not racing
eventpoll_release_file() on this epi, so drop the now-redundant
re-check of epi->dying under f_lock. The cheap lockless
READ_ONCE(epi->dying) fast-path bailout stays.

Comment 6 errata-xmlrpc 2026-07-07 09:36:27 UTC
This issue has been addressed in the following products:

  NVIDIA for RHEL 10

Via RHSA-2026:36186 https://access.redhat.com/errata/RHSA-2026:36186

Comment 7 errata-xmlrpc 2026-07-08 05:05:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:36541 https://access.redhat.com/errata/RHSA-2026:36541

Comment 8 errata-xmlrpc 2026-07-08 11:36:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:36645 https://access.redhat.com/errata/RHSA-2026:36645

Comment 9 errata-xmlrpc 2026-07-10 12:51:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:37729 https://access.redhat.com/errata/RHSA-2026:37729

Comment 10 errata-xmlrpc 2026-07-13 12:50:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:38902 https://access.redhat.com/errata/RHSA-2026:38902

Comment 11 errata-xmlrpc 2026-07-14 16:41:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:39371 https://access.redhat.com/errata/RHSA-2026:39371

Comment 14 errata-xmlrpc 2026-07-21 15:13:27 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.22

Via RHSA-2026:40764 https://access.redhat.com/errata/RHSA-2026:40764

Comment 15 errata-xmlrpc 2026-07-21 15:20:21 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.21

Via RHSA-2026:40779 https://access.redhat.com/errata/RHSA-2026:40779

Comment 16 errata-xmlrpc 2026-07-21 15:20:33 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:40787 https://access.redhat.com/errata/RHSA-2026:40787


Note You need to log in before you can comment on or make changes to this bug.