Improper input validation in Linux kernel - CVE-2026-74472
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in ublk_ctrl_add_dev() when copying user-supplied dev_info fields. A local user can supply crafted state values to trigger a kernel oops and cause a denial of service.
A crafted ublksrv_pid value can also cause GET_DEV_INFO to report an unrelated task as the ublk server.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74472
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/127033b79383a3e78361d7e971588aa8849f5124
- https://git.kernel.org/stable/c/205feb72e5beb3140e4e1403b6cff30cf739bab9
- https://git.kernel.org/stable/c/b67ce16b26ad0f14cfd6071013840aa95f823bea
- https://git.kernel.org/stable/c/e65848e4ce352bac9e3465099354c8b8f845391f
- https://git.kernel.org/stable/c/ee41b00858ca65b4428e99efe39a4277c1f043d2