SB20260824244 - Improper Initialization in Linux kernel integrity ima
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Initialization (CVE-ID: CVE-2026-74592)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass integrity measurement and appraisal of truncated files.
The vulnerability exists due to improper state management in the integrity measurement architecture truncate hook handling when truncation is requested for a regular file. A local user can truncate a file to bypass integrity measurement and appraisal of truncated files.
The issue affects files whose IMA action cache flags are not reset after content changes caused by truncation.
Remediation
Install update from vendor's website.