Linux-mm Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] CVE-2026-74484: Fix introducing commit via .vulnerable
@ 2026-08-19  3:01 Ye Weihua
  2026-08-19  6:51 ` Greg KH
  0 siblings, 1 reply; 2+ messages in thread
From: Ye Weihua @ 2026-08-19  3:01 UTC (permalink / raw)
  To: gregkh, brauner, kees; +Cc: cve, linux-mm, yeweihua4

The introduced tag of CVE-2026-74484 is 21ca59b365c0
("binfmt_misc: enable sandboxed mounts", v6.7), not 948b701a607f,
because before sandboxed mounts an unprivileged user or container cannot
trigger the self-referential DoS in a restricted namespace.

Signed-off-by: Ye Weihua <yeweihua4@huawei.com>
---
 cve/published/2026/CVE-2026-74484.vulnerable | 1 +
 1 file changed, 1 insertion(+)
 create mode 100644 cve/published/2026/CVE-2026-74484.vulnerable

diff --git a/cve/published/2026/CVE-2026-74484.vulnerable b/cve/published/2026/CVE-2026-74484.vulnerable
new file mode 100644
index 000000000..39fb39f38
--- /dev/null
+++ b/cve/published/2026/CVE-2026-74484.vulnerable
@@ -0,0 +1 @@
+21ca59b365c091d583f36ac753eaa8baf947be6f
-- 
2.34.1



^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] CVE-2026-74484: Fix introducing commit via .vulnerable
  2026-08-19  3:01 [PATCH] CVE-2026-74484: Fix introducing commit via .vulnerable Ye Weihua
@ 2026-08-19  6:51 ` Greg KH
  0 siblings, 0 replies; 2+ messages in thread
From: Greg KH @ 2026-08-19  6:51 UTC (permalink / raw)
  To: Ye Weihua; +Cc: brauner, kees, cve, linux-mm

On Wed, Aug 19, 2026 at 03:01:03AM +0000, Ye Weihua wrote:
> The introduced tag of CVE-2026-74484 is 21ca59b365c0
> ("binfmt_misc: enable sandboxed mounts", v6.7), not 948b701a607f,
> because before sandboxed mounts an unprivileged user or container cannot
> trigger the self-referential DoS in a restricted namespace.
> 
> Signed-off-by: Ye Weihua <yeweihua4@huawei.com>
> ---
>  cve/published/2026/CVE-2026-74484.vulnerable | 1 +
>  1 file changed, 1 insertion(+)
>  create mode 100644 cve/published/2026/CVE-2026-74484.vulnerable
> 
> diff --git a/cve/published/2026/CVE-2026-74484.vulnerable b/cve/published/2026/CVE-2026-74484.vulnerable
> new file mode 100644
> index 000000000..39fb39f38
> --- /dev/null
> +++ b/cve/published/2026/CVE-2026-74484.vulnerable
> @@ -0,0 +1 @@
> +21ca59b365c091d583f36ac753eaa8baf947be6f
> -- 
> 2.34.1
> 
> 

Thanks for this, now applied and pushed out the updated records as well.

greg k-h


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-19  6:53 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-19  3:01 [PATCH] CVE-2026-74484: Fix introducing commit via .vulnerable Ye Weihua
2026-08-19  6:51 ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox