Out-of-bounds read in Linux kernel - CVE-2026-74507
Published: August 16, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in hidp_process_data() when processing a malformed HIDP numbered report response. A remote user can send a specially crafted Bluetooth HIDP data response to cause a denial of service.
Exploitation requires a connected HIDP peer.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74507
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/27cc0e603355c585f1e5da8398faa4d36d498188
- https://git.kernel.org/stable/c/34f53d27b81a16a02828c8fdfa4e02badc326f17
- https://git.kernel.org/stable/c/7e7162427659b70ea17cd41b1f79e2e64c246690
- https://git.kernel.org/stable/c/9c841f59e10b5d75c398a3fc6b2da448d2a2276b
- https://git.kernel.org/stable/c/b7ad105d46acd828e424454815e4cd31069e047a