Out-of-bounds read in Linux kernel - CVE-2026-74648
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in rtw_cfg80211_monitor_if_xmit_entry() when processing truncated monitor transmit frames. A local user can send a specially crafted truncated frame to disclose sensitive information or cause a denial of service.
The issue occurs after removal of the radiotap header while handling 802.11 headers and related calculated header spans.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74648
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/6829665d050983907b560173e49dcc6c11cb2730
- https://git.kernel.org/stable/c/7b0f62d2986a28e5e4188366bc2f4e2868b14790
- https://git.kernel.org/stable/c/7edd3adb0c80d70b4237640275c559610f438476
- https://git.kernel.org/stable/c/8b3e4ed9c35d3d3b64fcc23f4a1f22b37c1865b1
- https://git.kernel.org/stable/c/a3ac6d849de5f7abe14761d741bbb843ac793454
- https://git.kernel.org/stable/c/bd88f6289b7e483216a9c1df15a0460ef9b02cb6
- https://git.kernel.org/stable/c/c5e5d78743992e235b76d2ebe5a403d60315aa8a
- https://git.kernel.org/stable/c/f03398d835f5249c49546f0eb0d0df6792b95d5f