Use of Uninitialized Variable in Linux kernel - CVE-2026-74500
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to uninitialized memory in snd_rme_digiface_read_status() when handling a short vendor control-IN transfer from a USB device. A local user can trigger a short read and read the exposed data through /dev/snd/controlC* to disclose sensitive information.
The issue affects the RME Digiface status controls and can expose the full 16-byte status frame to user space.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74500
linux (Debian package) - update to 6.12.105-1