๐Ÿ” CVE Alert

CVE-2026-74671

UNKNOWN 0.0

ima: fix out-of-bounds read in xattr_verify()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ima: fix out-of-bounds read in xattr_verify() The digest-length check in xattr_verify() mixes int and size_t: if (xattr_len - sizeof(xattr_value->type) - hash_start >= iint->ima_hash->length) sizeof() yields size_t, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtraction runs. For a truncated xattr this underflows instead of going negative: a 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1) turns "1 - 1 - 1" into SIZE_MAX, which is trivially >= ima_hash->length. The check then passes and the following memcmp() reads iint->ima_hash->length bytes starting past the end of the buffer vfs_getxattr_alloc() allocated for it. Nothing upstream clamps xattr_len back into a safe range first: ima_get_hash_algo() only special-cases xattr_len < 2 to pick a default algorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than failing when no HMAC key is loaded, so a truncated security.ima value reaches the length check as-is. Rewrite the comparison so every operand stays a signed int and no implicit conversion to size_t can occur.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
3ea7a56067e663278470c04fd655adf809e72d4d < d823b5f4557083d1dd92096f796a78a2b1b06d10 3ea7a56067e663278470c04fd655adf809e72d4d < caeb105c15ea2431fa8da7ecfa242d0c68272426 3ea7a56067e663278470c04fd655adf809e72d4d < a784b4732ac7e51862b9b210c2d8b2ab9e83568c 3ea7a56067e663278470c04fd655adf809e72d4d < b6cb134707a2127d90a58d69dd818679cae8033c 3ea7a56067e663278470c04fd655adf809e72d4d < 7e515b6c9aab452a4f0734bd7208e4e780e164ca 3ea7a56067e663278470c04fd655adf809e72d4d < 27f3924061592d0ef6b04e16f48754b6cb6adf27 3ea7a56067e663278470c04fd655adf809e72d4d < dd04114af0d451091f7b8cbd26d9e37d011e9131 3ea7a56067e663278470c04fd655adf809e72d4d < 5ff232d31106f45ac87c3b64e1d35a0667777797
Linux / Linux
3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10 git.kernel.org: https://git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426 git.kernel.org: https://git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c git.kernel.org: https://git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c git.kernel.org: https://git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca git.kernel.org: https://git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27 git.kernel.org: https://git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131 git.kernel.org: https://git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797