Heap-based buffer overflow in Linux kernel - CVE-2026-74452
Published: August 16, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in panthor_fw_load_section_entry() and panthor_fw_init_section_mem() when parsing a crafted firmware section entry with oversized initial data. A local user can supply a crafted firmware to trigger memory corruption and cause a denial of service.
An oversized section data value can also cause an underflow in the zeroing size calculation, potentially leading to out-of-bounds kernel memory zeroing.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74452
linux (Debian package) - update to 6.12.105-1