CVE-2026-74258

Source
https://cve.org/CVERecord?id=CVE-2026-74258
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74258.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74258
Downstream
Published
2026-08-15T05:57:36Z
Modified
2026-09-22T03:45:29Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
bpf: Guard __get_user acesss with access_ok for uprobe_multi data
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Guard __get_user acesss with access_ok for uprobe_multi data

As reported by sashiko [1] we need to use access_ok to check the user space data bounds before we use __get-user to get it.

[1] https://lore.kernel.org/bpf/20260610145235.CB1441F00893@smtp.kernel.org/

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74258.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
89ae89f53d201143560f1e9ed4bfa62eee34f88e
Fixed
2c387db784293256d35fd3d438f577cc82bb823d
Fixed
a9f1395028c2bbe18e57864cc355c11faff488cb
Fixed
c6d51ad36490013ee9df94a372d3bf794bd304d1
Fixed
4d87a251d45b4a95eb4c0abcfab809c9f231258a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74258.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74258.json"