SB20260816253 - Improper input validation in Linux kernel block driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-74472)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in ublk_ctrl_add_dev() when copying user-supplied dev_info fields. A local user can supply crafted state values to trigger a kernel oops and cause a denial of service.
A crafted ublksrv_pid value can also cause GET_DEV_INFO to report an unrelated task as the ublk server.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124
- https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9
- https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea
- https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f
- https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2