Out-of-bounds read in Linux kernel - CVE-2026-74751
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the riscv ZBB-optimized strnlen implementation when processing memory ranges whose end falls on a page boundary. A remote attacker can trigger the vulnerable code path to cause a denial of service.
The issue occurs when the requested count ends exactly at an aligned boundary and the following page is unmapped.