Memory corruption in Linux kernel - CVE-2026-74551
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to improper memory alignment in the nzxt-smart2 driver output buffer when sending output reports through the USB HID core for DMA. A local user can trigger device operations such as setting a fan speed or updating the interval to cause memory corruption.
This issue affects systems with non-coherent CPU architectures such as ARM or MIPS, where the corruption is immediate and deterministic due to cacheline sharing with adjacent variables.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74551
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/080bbf42faf77e6489ab30d5114c5f8f6ccbb1b8
- https://git.kernel.org/stable/c/2332d35aaf206c17acf848522817252732596676
- https://git.kernel.org/stable/c/51a76bc1b8e717ee3fc0d84f15ac51490ca5f76f
- https://git.kernel.org/stable/c/6a2dbce5da2d2163a5b684acf68a0e54582ff0fa
- https://git.kernel.org/stable/c/70ad543ce81f368411b6c721265a3b2d7ab4fda4