Improper Initialization in Linux kernel - CVE-2026-74592
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to bypass integrity measurement and appraisal of truncated files.
The vulnerability exists due to improper state management in the integrity measurement architecture truncate hook handling when truncation is requested for a regular file. A local user can truncate a file to bypass integrity measurement and appraisal of truncated files.
The issue affects files whose IMA action cache flags are not reset after content changes caused by truncation.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74592
linux (Debian package) - update to 6.12.105-1