Heap Out-of-Bounds Read in Linux Kernel NCSI Command Handling
CVE-2026-74694
What is CVE-2026-74694?
A vulnerability in the Linux kernel's NCSI command handling allows attackers to exploit heap out-of-bounds read conditions. The issue arises when ncsi_send_cmd_nl() processes an attacker-controlled packet header without sufficient length verification, allowing a buffer read beyond the allocated memory. This can potentially lead to sensitive information leakage from kernel memory, which is especially critical on systems utilizing NCSI devices such as OpenBMC on Aspeed BMC SoCs. The vulnerability highlights the importance of robust input validation within kernel operations to mitigate risks.
Affected Version(s)
Linux 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392
Linux 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 < 67c72b8ef63d9d9a610546fda30b116638f39745
Linux 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 < 4489b4a17892750131e4bef4bc1d3d703c8fb5ba