CVE-2026-74259
Linux kernel CIFS unmount null-pointer can crash kernel (Denial of Service).
Is CVE-2026-74259 being exploited?
Not confirmed. CVE-2026-74259 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.18% probability of exploitation in the next 30 days.
How severe is CVE-2026-74259?
CVE-2026-74259 is rated High with a CVSS score of 8.4. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74259?
Yes. A fix has been recorded for CVE-2026-74259. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74259 affect?
CVE-2026-74259 affects Linux kernel (cifs module), Linux distributions using CIFS/SMB mounts. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74259?
Apply vendor/kernel updates or avoid/unmount CIFS mounts until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Null-pointer deref in CIFS during unmount can crash the kernel, causing host/service denial-of-service via CIFS mount/unmount operations.
Patch when possible
- affected>= 708c276f516d27beaded7f372ac8111cee43926c and < 55fb9581986141659002264fdc75cef307811eb8
- affected>= 0629a1a187e424373364d681b42b101894bdb548 and < 4465ebe67d89345954bb3622b25dd13e06f9d367
- affected>= 0e4b8faaaebe3137bec5723ef2b3cb0437fb38fd and < 3baedc9b2f53e6a6ac57b16fdff0f9b954d9ca71
- affected>= f655467a9973f964b267871e5fef533ad5014494 and < 21303c4a2b7275e626c6b67de0f45f2d5b9bb3e7
- affected>= 340cea84f691c5206561bb2e0147158fe02070be and < 7839f1817a0cb6c4ed5cfe25d04845c43380a129
- affected>= 340cea84f691c5206561bb2e0147158fe02070be and < 6d9a4aaaa8b2612b5ef9d581e2f286a458b71ee1
- affected30afc6ea72cc6cf7c8d579e79b64232801c38d08
- affected>= 6.1.167 and < 6.1.178
- affected>= 6.6.130 and < 6.6.145
- affected>= 6.12.78 and < 6.12.97
- affected>= 6.18.20 and < 6.18.40
- affected>= 6.19.10 and < 6.20
- affected7.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.