---
id: CVE-2026-74590
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions

  The BPF verifier and the dynptr abstraction ensure that the memory space
  referenced by a dynptr remains vali…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions

  The BPF verifier and the dynptr abstraction ensure that the memory space
  referenced by a dynptr remains vali…
severity: none
published: '2026-08-22'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74590'
references:
  - url: 'https://git.kernel.org/stable/c/1344b632cb5043e32939a84568125719111c5af3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2a5cfcad1d56e26d645b7887b0ed24c371851525'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3e8ec7c0387273329374f5c7bd61f5f38af71fe1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5bd63cad9df4328a184c409fbdad4f17944bcdb8'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
ingestedAt: '2026-08-23T06:43:33.713Z'
epss: 0.00175
epssPercentile: 0.06172
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions

The BPF verifier and the dynptr abstraction ensure that the memory space
referenced by a dynptr remains valid.  They do not, however, provide any
guarantee that the contents of the memory are stable.  kfuncs are
expected to remain memory-safe even if concurrent modifications occur.

bpf_get_fsverity_digest() didn't follow that: it could crash if
arg->digest_size was concurrently modified.

Fix that by using the known-good value hash_alg->digest_size instead.

Also widen 'dynptr_sz' and 'out_digest_sz' to u64 to match the return
type of __bpf_dynptr_size().  It doesn't appear that it can actually be
more than INT_MAX currently (since __bpf_dynptr_data_rw() excludes
file-based pointers), but the correct type might as well be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
