Memory corruption in Linux kernel - CVE-2026-74551

 

Memory corruption in Linux kernel - CVE-2026-74551

Published: August 16, 2026


Vulnerability identifier: #VU143230
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74551
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause memory corruption.

The vulnerability exists due to improper memory alignment in the nzxt-smart2 driver output buffer when sending output reports through the USB HID core for DMA. A local user can trigger device operations such as setting a fan speed or updating the interval to cause memory corruption.

This issue affects systems with non-coherent CPU architectures such as ARM or MIPS, where the corruption is immediate and deterministic due to cacheline sharing with adjacent variables.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74551

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins