Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74522

8.8 · HIGH
Published Aug 15, 2026 EPSS 0.43% (36th pctl)

Overview

CVE-2026-74522 is a high-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 8.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix use-after-free in __close_file_table_ids()

A ksmbd_file can remain alive after logical close while another session

holds a temporary reference obtained through ksmbd_lookup_fd_inode().

ksmbd_close_fd() currently marks the file closed and drops the idr-owned

reference, but leaves the pointer published in the closing session's idr

until the final reference is dropped.

If the foreign holder performs the final ksmbd_fd_put(), __put_fd_final()

supplies the foreign session's file table to __ksmbd_close_fd(). The object

is then freed without being removed from its owner's idr, and the owner

session later dereferences the stale pointer during file-table teardown.

Remove the volatile id from the owner's idr while ksmbd_close_fd() still

holds that table's lock, and clear volatile_id before dropping

the idr-owned reference. A later foreign final put then only performs

physical destruction and cannot remove the obje

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74522?

CVE-2026-74522 is a high-severity vulnerability. It was published on August 15, 2026 and has a CVSS 3.1 base score of 8.8 (HIGH).

How severe is CVE-2026-74522?

This vulnerability has a CVSS 3.1 base score of 8.8, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2026-74522?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74522?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74522 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.