Out-of-bounds write in Linux kernel - CVE-2026-74498
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service or corrupt kernel memory.
The vulnerability exists due to an out-of-bounds write in the ALSA USB audio endpoint DMA buffer handling in data_ep_set_params() when processing USB audio endpoints with the fill_max descriptor flag set. A local user can trigger oversized packet transfers to cause a denial of service or corrupt kernel memory.
The issue occurs because the allocated buffer size is based on the original sample-rate-derived value while transfer packets may use the larger maximum packet size.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74498
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/04595233e5606d452f9f47e6989fc7ae7440fd40
- https://git.kernel.org/stable/c/3852974608f53e530e27c21d0c6c7d79c17b3f5a
- https://git.kernel.org/stable/c/bd65b7191683bebd9923904f0558b9211b9129da
- https://git.kernel.org/stable/c/d0199ae1666ff9ae2d1d568d64c3430d4c47f0e5
- https://git.kernel.org/stable/c/f9b6c9576568169139ac151f7881474f384659fd