Out-of-bounds write in Linux kernel - CVE-2026-74616
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in xdpf_clone() and the XDP-to-skb conversion path when converting crafted cloned XDP frames into sk_buffs. A local user can trigger conversion of a crafted clone that overlaps skb_shared_info tailroom to cause memory corruption.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74616
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/58408982fa39f9758124cec169f42854d6f98f35
- https://git.kernel.org/stable/c/685edea27ac68d08fe4dbd3de74b858d2ad8e830
- https://git.kernel.org/stable/c/ba13763d667e008e185fedf592d53846a5b457d1
- https://git.kernel.org/stable/c/e48e8edbef2eb824201495daa5234560f632b23c
- https://git.kernel.org/stable/c/ef4b7c7046d29a67090de15af0da0d1ae8d1b192
- https://git.kernel.org/stable/c/f463b6f4957c9c3fd1c75f8d3e5af4879fa609c0
- https://git.kernel.org/stable/c/fab820f1691a9e26d9031f18aae1e9ce09078f92