Out-of-bounds read in Linux kernel - CVE-2026-74598

 

Out-of-bounds read in Linux kernel - CVE-2026-74598

Published: August 24, 2026


Vulnerability identifier: #VU144960
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74598
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an out-of-bounds read in rt6_route_rcv() when processing a crafted IPv6 Router Advertisement containing a malformed Route Information option. A remote attacker can send a specially crafted Router Advertisement to disclose sensitive information.

When additional options follow the malformed Route Information option, data from the next option can be incorporated into the installed route and become visible to userspace.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74598

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins