Out-of-bounds write in Linux kernel - CVE-2026-74640
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to overwrite kernel memory and cause a denial of service.
The vulnerability exists due to an out-of-bounds write in fcp_meter_ctl_get() when reading ALSA FCP controls with an oversized user-defined meter map. A local user can read a crafted control value to overwrite kernel memory and cause a denial of service.
Installing the oversized meter map requires CAP_SYS_RAWIO, but the created control can later be read by an unprivileged process through /dev/snd/controlC0.