Improper input validation in Linux kernel - CVE-2026-74453

 

Improper input validation in Linux kernel - CVE-2026-74453

Published: August 16, 2026


Vulnerability identifier: #VU143337
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74453
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in validate_tile_binning_config when processing tile binning configurations with oversized tile state arrays. A local user can submit a crafted tile binning configuration that leaves no room for the tile allocation pool to cause a denial of service.

The tile state data array size is derived from tile count fields and shares the same buffer slot with the tile allocation pool.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74453

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins