Out-of-bounds read in Linux kernel - CVE-2026-74557
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in iscsi_scsi_cmd_rsp() when processing a target-supplied SCSI Response sense data segment. A remote attacker can send a crafted SCSI Response with a malformed sense length field to disclose sensitive information.
The over-read can copy up to two bytes of stale conn->data contents into the command's sense buffer, which is returned to userspace.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74557
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/1f07a897d43c63e6c9458bf77450defef39b5833
- https://git.kernel.org/stable/c/3ef209ca0b4b68c75e9a814d90cc916026b5a6ac
- https://git.kernel.org/stable/c/60499924faf4ef97e84228c20515218ef121facf
- https://git.kernel.org/stable/c/7567f06abdefb1caf2d836107c4d08c5185c650e
- https://git.kernel.org/stable/c/98b87885de4b7f605533a2860685f5689fce8e82