CVE-2026-74671

Source
https://cve.org/CVERecord?id=CVE-2026-74671
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74671.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74671
Downstream
Published
2026-08-22T15:32:41.480Z
Modified
2026-08-24T11:47:21.314544586Z
Summary
ima: fix out-of-bounds read in xattr_verify()
Details

In the Linux kernel, the following vulnerability has been resolved:

ima: fix out-of-bounds read in xattr_verify()

The digest-length check in xattrverify() mixes int and sizet:

if (xattr_len - sizeof(xattr_value->type) - hash_start >=
        iint->ima_hash->length)

sizeof() yields sizet, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtraction runs. For a truncated xattr this underflows instead of going negative: a 1-byte IMAXATTRDIGESTNG xattr (xattrlen == 1, hashstart == 1) turns "1 - 1 - 1" into SIZEMAX, which is trivially >= imahash->length. The check then passes and the following memcmp() reads iint->imahash->length bytes starting past the end of the buffer vfsgetxattr_alloc() allocated for it.

Nothing upstream clamps xattrlen back into a safe range first: imagethashalgo() only special-cases xattrlen < 2 to pick a default algorithm, and evmverifyxattr() returns INTEGRITY_UNKNOWN rather than failing when no HMAC key is loaded, so a truncated security.ima value reaches the length check as-is.

Rewrite the comparison so every operand stays a signed int and no implicit conversion to size_t can occur.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74671.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3ea7a56067e663278470c04fd655adf809e72d4d
Fixed
d823b5f4557083d1dd92096f796a78a2b1b06d10
Fixed
caeb105c15ea2431fa8da7ecfa242d0c68272426
Fixed
a784b4732ac7e51862b9b210c2d8b2ab9e83568c
Fixed
b6cb134707a2127d90a58d69dd818679cae8033c
Fixed
7e515b6c9aab452a4f0734bd7208e4e780e164ca
Fixed
27f3924061592d0ef6b04e16f48754b6cb6adf27
Fixed
dd04114af0d451091f7b8cbd26d9e37d011e9131
Fixed
5ff232d31106f45ac87c3b64e1d35a0667777797

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74671.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.13.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74671.json"