{"id":"CVE-2026-74590","summary":"fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfsverity: Fix bpf_get_fsverity_digest() dynptr assumptions\n\nThe BPF verifier and the dynptr abstraction ensure that the memory space\nreferenced by a dynptr remains valid.  They do not, however, provide any\nguarantee that the contents of the memory are stable.  kfuncs are\nexpected to remain memory-safe even if concurrent modifications occur.\n\nbpf_get_fsverity_digest() didn't follow that: it could crash if\narg-\u003edigest_size was concurrently modified.\n\nFix that by using the known-good value hash_alg-\u003edigest_size instead.\n\nAlso widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return\ntype of __bpf_dynptr_size().  It doesn't appear that it can actually be\nmore than INT_MAX currently (since __bpf_dynptr_data_rw() excludes\nfile-based pointers), but the correct type might as well be used.","modified":"2026-08-27T11:30:33.204874177Z","published":"2026-08-22T15:31:41.929Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74590.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1344b632cb5043e32939a84568125719111c5af3"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2a5cfcad1d56e26d645b7887b0ed24c371851525"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3e8ec7c0387273329374f5c7bd61f5f38af71fe1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5bd63cad9df4328a184c409fbdad4f17944bcdb8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74590.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74590"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"67814c00de3161181cddd06c77aeaf86ac4cc584"},{"fixed":"1344b632cb5043e32939a84568125719111c5af3"},{"fixed":"2a5cfcad1d56e26d645b7887b0ed24c371851525"},{"fixed":"5bd63cad9df4328a184c409fbdad4f17944bcdb8"},{"fixed":"3e8ec7c0387273329374f5c7bd61f5f38af71fe1"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74590.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.8.0"},{"fixed":"6.12.104"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.45"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74590.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}