CVE-2026-74634

Summary

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Prevent subbuf order change when resizing is disabled

Because ring_buffer_subbuf_order_set() frees buffer pages, we can't allow it when resizing is disabled. A non-consuming reader is at risk of use-after-free (rb_advance_iter()).

Return -EBUSY on resize_disabled, matching ring_buffer_resize() behaviour.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf9b94daa542a8d2532f0930f01cd9aec2d19621b < b45b91db41379ee5fb36c187d6d7c37b725cbe8eaffected
LinuxLinuxf9b94daa542a8d2532f0930f01cd9aec2d19621b < 62978cf6347972c04130e4e841ba404504d92b32affected
LinuxLinuxf9b94daa542a8d2532f0930f01cd9aec2d19621b < 7568e9e717e7540bd05bcc007f5d76fcaff3cdffaffected
LinuxLinuxf9b94daa542a8d2532f0930f01cd9aec2d19621b < bf98d7b0d5a99991e47e66cee4eb1d3fa514be97affected
LinuxLinux6.8affected
LinuxLinux0 < 6.8unaffected
LinuxLinux6.12.104 <= 6.12.*unaffected
LinuxLinux6.18.45 <= 6.18.*unaffected
LinuxLinux7.1.9 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References