๐Ÿ” CVE Alert

CVE-2026-74399

UNKNOWN 0.0

evm: terminate and bound the evm_xattrs read buffer

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: evm: terminate and bound the evm_xattrs read buffer evm_read_xattrs() allocates size + 1 bytes, fills them from the list of enabled xattrs, and then passes strlen(temp) to simple_read_from_buffer(). When no configured xattrs are enabled, the fill loop stores nothing and temp[0] remains uninitialized, so strlen() reads beyond initialized memory. Explicitly terminate the buffer after allocation, use snprintf() for each formatted line, and pass the accumulated length, without risk of truncation, to simple_read_from_buffer().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 8df81954d22a653a8b01d46692cd56f71137269b fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 0b9f8282b40af4a99d6243d2cb939d14ff36b049 fa516b66a1bfce1d72f1620c54bdfebc493000d1 < a36cbfb85f26e6c6fb6529b1a364331b94dc88f3 fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 12ad52dc45a0c8c9d25e85b4a84201de4c5420ed fa516b66a1bfce1d72f1620c54bdfebc493000d1 < a0f64cf8bfcb39e533d9e27aeb763a8d81b7f39d fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 38b7d63b23aa9d2ddde7688040e9426d32be4065 fa516b66a1bfce1d72f1620c54bdfebc493000d1 < 11143a19f5b8dc8f414deab87571134f9f447313
Linux / Linux
4.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8df81954d22a653a8b01d46692cd56f71137269b git.kernel.org: https://git.kernel.org/stable/c/0b9f8282b40af4a99d6243d2cb939d14ff36b049 git.kernel.org: https://git.kernel.org/stable/c/a36cbfb85f26e6c6fb6529b1a364331b94dc88f3 git.kernel.org: https://git.kernel.org/stable/c/12ad52dc45a0c8c9d25e85b4a84201de4c5420ed git.kernel.org: https://git.kernel.org/stable/c/a0f64cf8bfcb39e533d9e27aeb763a8d81b7f39d git.kernel.org: https://git.kernel.org/stable/c/38b7d63b23aa9d2ddde7688040e9426d32be4065 git.kernel.org: https://git.kernel.org/stable/c/11143a19f5b8dc8f414deab87571134f9f447313