SB20260824244 - Improper Initialization in Linux kernel integrity ima



SB20260824244 - Improper Initialization in Linux kernel integrity ima

Published: August 24, 2026

Security Bulletin ID SB20260824244
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Initialization (CVE-ID: CVE-2026-74592)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to bypass integrity measurement and appraisal of truncated files.

The vulnerability exists due to improper state management in the integrity measurement architecture truncate hook handling when truncation is requested for a regular file. A local user can truncate a file to bypass integrity measurement and appraisal of truncated files.

The issue affects files whose IMA action cache flags are not reset after content changes caused by truncation.


Remediation

Install update from vendor's website.