Buffer Overflow Vulnerability in Linux Kernel Affects Multiple Systems
CVE-2026-74399
Currently unrated
What is CVE-2026-74399?
A buffer overflow vulnerability exists in the Linux kernel's handling of extended attribute reads, specifically in the evm_read_xattrs() function. When there are no configured extended attributes enabled, the read buffer may remain uninitialized. This issue allows the function to read beyond initialized memory, potentially leading to exploitation. Proper memory management practices, such as explicit buffer termination and controlled string formatting, are crucial to mitigate this risk.
Affected Version(s)
Linux fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 8df81954d22a653a8b01d46692cd56f71137269b
Linux fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 0b9f8282b40af4a99d6243d2cb939d14ff36b049
Linux fa516b66a1bfce1d72f1620c54bdfebc493000d1