Out-of-bounds read in Linux kernel - CVE-2026-74410
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in rtw_pci_rx_napi() when processing firmware RX descriptors on the PCIe transport path. A local attacker can provide a crafted descriptor with a length value that exceeds the DMA buffer size to disclose sensitive information.
The issue occurs because the computed receive length can exceed the size of the pre-allocated DMA buffer before data is copied.
Affected software
Ubuntu
linux-nvidia-tegra (Ubuntu package)
How to mitigate CVE-2026-74410
linux-nvidia-tegra (Ubuntu package) - update to 6.8.0-1035.38
External References
- https://git.kernel.org/stable/c/01155ded5d4dad61840a9a3c33ab56778ef1f100
- https://git.kernel.org/stable/c/08193e733e5d4790e6c937af86d78793b02709be
- https://git.kernel.org/stable/c/1554fa522f16ec7c5c342ad33fe734eeb6eb2452
- https://git.kernel.org/stable/c/26c183a86ea4dd1f2ff90c6f783649e7f5722a10
- https://git.kernel.org/stable/c/45abc14ab3f15da7d689f1a8809c1a01240a94d9
- https://git.kernel.org/stable/c/6a3c384393d3f0b41669ed5a2e88744aad9d87c8
- https://git.kernel.org/stable/c/6e76e9ed273dfb4b3333a5ebbb94958cc5752ab6
- https://git.kernel.org/stable/c/913bd7d3d3d842b5c1d2b908a0201efa8fc79793