Linux kernel NFS bug affects widespread OS kernels and can cause crashes or kernel compromise across many servers and endpoints.
CVE-2026-74730
Linux kernel NFS use-after-free (FREE_STATEID) may allow kernel crash or code execution.
Is CVE-2026-74730 being exploited?
Not confirmed. CVE-2026-74730 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.51% probability of exploitation in the next 30 days.
How severe is CVE-2026-74730?
CVE-2026-74730 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74730?
Yes. A fix has been recorded for CVE-2026-74730. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74730 affect?
CVE-2026-74730 affects Linux kernel (NFS subsystem), NFS clients and servers, Major distros: Ubuntu, RHEL, Debian, SUSE, etc.. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74730?
Apply vendor kernel updates for NFS and reboot; restrict NFS access until patched.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Use-after-free in NFS can crash the kernel (DoS) or enable kernel-level code execution, leading to full system compromise.
Immediate action required
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < ed2f92ce2fc48463c41e0e540b9a3454889e8af8
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < d858ab09e787106432d4d9830bad9dfedf02f890
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < af62f1af182d33a0de38308c012841885d8ab92e
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < caee6a68ffaa5016dfc01cd0b3dc1896a32e3abd
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < ed1161ab6239761958b38d5667225634fc2be894
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < d71dfffa512e71b166a889484e4c3b148a9a3af2
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < 80ed3d762628b36c9e4b22fac7c65b72ef3b13dd
- affected>= 7c1d5fae4a87d3cf3e9ffd68bcdbaf6529013009 and < cf616096a0f3a2b60f7d68b6b39674a6867ded9c
- affected3.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.