Improper input validation in Linux kernel - CVE-2026-74497
Published: August 16, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper input validation in snd_usb_handle_sync_urb() when processing oversized USB sync packets in implicit-feedback mode. An attacker with physical access can connect a crafted USB device that sends oversized sync packets to cause a denial of service.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74497
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/2db4535d6af79276a64449201c5be5feffb31c64
- https://git.kernel.org/stable/c/53f0aa37eb945f3c983f61d12fc35eb33debb8a9
- https://git.kernel.org/stable/c/56ac3e7c90f6b45969c3fd07a98fad760ffd6901
- https://git.kernel.org/stable/c/8d7a30c50c2e58a6839634ed0acde14466d1dc61
- https://git.kernel.org/stable/c/be97fea7451d758881b95af78e900dd0d58a382a