CVE-2026-74313
Linux kernel vduse use-after-free race in device open path.
Is CVE-2026-74313 being exploited?
Not confirmed. CVE-2026-74313 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-74313?
CVE-2026-74313 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74313?
Yes. A fix has been recorded for CVE-2026-74313. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74313 affect?
CVE-2026-74313 affects Linux kernel (vduse subsystem). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74313?
Apply vendor/kernel updates that fix the vduse race and reboot affected systems.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Use-after-free during vduse device open can cause kernel memory corruption, crashes, or local privilege escalation/remote code execution via kernel compromise.
Patch when possible
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < 35483c5306e09b3190ff937089d404a78012695c
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < 5c1560be8aa6849356455af67518d35c551cbd95
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < 93ed4692f2299a40346025979f40e4a9b7b33af7
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < d94e2947203aead590fd63f667d316d4475d65af
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < a2d0a57538fd0b3b3ab75d64bb64f4cd2fab13a2
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < 79e12c891940b0c4c75881b7fd82a8cbb8ac97be
- affected>= c8a6153b6c59d95c0e091f053f6f180952ade91e and < e440e077748939839d9f76e24383b76b785f80ce
- affected5.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.