Out-of-bounds read in Linux kernel - CVE-2026-74585
Published: August 24, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to an out-of-bounds pointer dereference in tb_drom_parse_entry_port() in the thunderbolt DROM parser when processing a malicious or malformed Thunderbolt device DROM. An attacker with physical access can supply a crafted Thunderbolt device with an invalid dual_link_port_nr value to cause a denial of service.
The invalid pointer is stored and later dereferenced after indexing sw->ports[] beyond the configured maximum port number.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74585
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/3d3c212b70633332ab71672aa2bc6af257d2ec83
- https://git.kernel.org/stable/c/40d2ffb74094cf36edbe05855566a4c58b6ce808
- https://git.kernel.org/stable/c/50f0c8dd8c3390f851cfb97ca13116f9ee6469d1
- https://git.kernel.org/stable/c/6c892ed9f4129ae40ef0f92e1bb31aa0b0ddc72c
- https://git.kernel.org/stable/c/b98e1e28bd95b0fa33164eec1e763d26c7058b39
- https://git.kernel.org/stable/c/d6764992f17b23d91ff93ce905ab53c2aa7191f0
- https://git.kernel.org/stable/c/f28066057134aa9294caa597b670daf505ad9dce
- https://git.kernel.org/stable/c/f32c3a9a77cfb50934a60b05d5407649af062535