Use of uninitialized resource in Linux kernel - CVE-2026-74659
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to uninitialized memory exposure in br_mrp_alloc_test_skb() when constructing MRA MRP_Test frames. A remote attacker can trigger transmission of a specially crafted protocol frame to disclose sensitive information.
Three uninitialized bytes are present in each transmitted MRA MRP_Test frame because the sub-TLV length field and alignment padding are not initialized.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74659
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/014c062d23c63ec77ef2cf17a0d9363c7441cc94
- https://git.kernel.org/stable/c/06d58b8d2f053ced82e01efaeb6e7c82891eed58
- https://git.kernel.org/stable/c/5912cf1822fbe53ae275c147868740eb384a5d3e
- https://git.kernel.org/stable/c/63488dba65ef91373ef616575b32eb0eb21459f4
- https://git.kernel.org/stable/c/7ebc23ff03668042e0b0e4034bb1518d36198d9e
- https://git.kernel.org/stable/c/a5e385eeb2d6dbbbdebfa050e67c34734ae12693
- https://git.kernel.org/stable/c/e08665218040f8e312abe40f74543186f3c2c941