Slab-Out-Of-Bounds Read Vulnerability in Linux Kernel Networking
CVE-2026-74689
What is CVE-2026-74689?
A vulnerability in the Linux kernel's networking subsystem could allow for slab-out-of-bounds reads due to an ineffective length check in the vcc_setsockopt() function. If the option level does not match the expected value, the length check can be bypassed, potentially leading to memory access violations. This issue can occur if a caller sends mismatched parameters, or if certain filters manipulate the option length, resulting in unsafe memory operations. The vulnerability has now been addressed by changing the method used to validate input lengths and ensuring proper data type alignment.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 35f258fee9ed358c6d0f57f91c30bf029c3724af
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6eb6af88710977eb529b558a07294874d8c40c4d