Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74351

Published Aug 15, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-74351 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: rebase copied fsdlm LVB pointers in locking_state

The locking_state debugfs iterator snapshots struct ocfs2_lock_res by

value under ocfs2_dlm_tracking_lock and later formats that copy in

ocfs2_dlm_seq_show(). That is fine for the inline fields, but the

userspace fsdlm stack stores the LVB through lksb_fsdlm.sb_lvbptr. Once

the iterator drops the tracking lock, a copied non-NULL sb_lvbptr still

points into the original lockres owner, so teardown can free that

container before the debugfs dump walks the raw LVB bytes.

Rebase the copied sb_lvbptr to the copied l_lksb before dumping the raw

LVB. The seq snapshot already carries the inline LVB storage reserved in

struct ocfs2_dlm_lksb, so the debugfs reader can dump the copied bytes

without borrowing the original lockres lifetime.

The buggy scenario involves two paths, with each column showing the order

within that path:

locking_state reader:

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74351?

CVE-2026-74351 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-74351?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74351?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74351?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74351 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.