Out-of-bounds read in Linux kernel - CVE-2026-74671
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in xattr_verify() when verifying a truncated security.ima extended attribute value. A local user can provide a specially crafted truncated extended attribute to disclose sensitive information.
The issue is triggered by an integer underflow caused by mixing signed and unsigned arithmetic in the digest-length check.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74671
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27
- https://git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797
- https://git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca
- https://git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c
- https://git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c
- https://git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426
- https://git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10
- https://git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131