Improper Initialization in Linux kernel - CVE-2026-74577
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper initialization in mpls_getroute() when handling RTM_GETROUTE requests. A local user can send a crafted netlink route request to disclose sensitive information.
The issue leaks one byte of uninitialized heap memory to user space in the RTM_NEWROUTE reply.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74577
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1fea5ff0eb4aa7e951bb3d380248566c473aa377
- https://git.kernel.org/stable/c/295dd295e2137e10e9a5b1891d97e0f08de76f03
- https://git.kernel.org/stable/c/2dc2fffc704a4365cae1aae078ba62223aaeff93
- https://git.kernel.org/stable/c/95651461cf77cc6590fa08c87667717e5dcfa55d
- https://git.kernel.org/stable/c/a5cdd2407dd890f741f59b8367e4c6c101cce154