Out-of-bounds read in Linux kernel - CVE-2026-74648

 

Out-of-bounds read in Linux kernel - CVE-2026-74648

Published: August 24, 2026


Vulnerability identifier: #VU144870
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74648
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information or cause a denial of service.

The vulnerability exists due to out-of-bounds read in rtw_cfg80211_monitor_if_xmit_entry() when processing truncated monitor transmit frames. A local user can send a specially crafted truncated frame to disclose sensitive information or cause a denial of service.

The issue occurs after removal of the radiotap header while handling 802.11 headers and related calculated header spans.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74648

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins