Out-of-Bounds Read Vulnerability in Linux Kernel Affects Multiple Products
CVE-2026-74410
What is CVE-2026-74410?
This vulnerability in the Linux kernel affects the RTW88 wireless driver by allowing an out-of-bounds read due to improperly calculated lengths in packet descriptors. The issue arises when the sum of the packet length and offset exceeds the allowable size of the DMA buffer, risking sensitive data exposure and potential security breaches. While USB transport protocols provide validation checks, the PCIe implementation lacks this layer of security. A patch has been introduced to validate the new length against the DMA buffer limit, mitigating potential exploitation.
Affected Version(s)
Linux e3037485c68ec1a299ff41160d8fedbd4abc29b9 < 913bd7d3d3d842b5c1d2b908a0201efa8fc79793
Linux e3037485c68ec1a299ff41160d8fedbd4abc29b9 < 45abc14ab3f15da7d689f1a8809c1a01240a94d9
Linux e3037485c68ec1a299ff41160d8fedbd4abc29b9 < 08193e733e5d4790e6c937af86d78793b02709be