CVE-2026-74567

HIGHCVSS 7.1/10EPSS 0.12%

Last modified

CVE-2026-74567 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chunk() For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup(desc, desc_len + 1) allocation. Compute the full byte offset and bounds-check the description against it before reading. The walk only reaches a description-level chunk when two keys collide through the hash, x, type and domain_tag chunks, so this is reached from an unprivileged add_key(2) with a crafted pair of same-type keys whose index hashes collide; KASAN reports a slab-out-of-bounds read.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chunk() For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup(desc, desc_len + 1) allocation. Compute the full byte offset and bounds-check the description against it before reading. The walk only reaches a description-level chunk when two keys collide through the hash, x, type and domain_tag chunks, so this is reached from an unprivileged add_key(2) with a crafted pair of same-type keys whose index hashes collide; KASAN reports a slab-out-of-bounds read.

Metrics

CVSS 3.1
7.1/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

EPSS Probability
0.12%

1.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f771fde82051976a6fc0fd570f8b86de4a92124b, < 4c0c26f751e50d3027eacc4d7d0fabc31f1d7e6b; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < 79916f40d4ab1b4ae694d8c024fd179454bfe46e; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < e5b01998cef8d7f613200230ccaadebe5de9135c; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < d1933e03e8c74a018550c31a393b79c4d95bff40; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < 3a744838453fb9309ce5a5526d3252e211d60152; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < e9417d21a22ad2ec398e78fcf084b717ce92cf2f; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < 8dba33c1e779d0fb9a2acb31e354cf0fc0229111; >= f771fde82051976a6fc0fd570f8b86de4a92124b, < 63918731f9ae25b5deb022f118e941e6dddfcef4
LinuxLinux5.3

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74567?
In the Linux kernel, the following vulnerability has been resolved: keys: fix out-of-bounds read in keyring_get_key_chunk() For description-level chunks keyring_get_key_chunk() advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup(desc, desc_len + 1) allocation. Compute the full byte offset and bounds-check the description against it before reading. The walk only reaches a description-level chunk when two keys collide through the hash, x, type and domain_tag chunks, so this is reached from an unprivileged add_key(2) with a crafted pair of same-type keys whose index hashes collide; KASAN reports a slab-out-of-bounds read.
How severe is CVE-2026-74567?
CVE-2026-74567 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2026-74567?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74567?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST