Improper Initialization in Linux kernel - CVE-2026-74592

 

Improper Initialization in Linux kernel - CVE-2026-74592

Published: August 24, 2026


Vulnerability identifier: #VU144971
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74592
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass integrity measurement and appraisal of truncated files.

The vulnerability exists due to improper state management in the integrity measurement architecture truncate hook handling when truncation is requested for a regular file. A local user can truncate a file to bypass integrity measurement and appraisal of truncated files.

The issue affects files whose IMA action cache flags are not reset after content changes caused by truncation.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74592

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins