CVE-2026-74676

Unknown

Last modified

CVE-2026-74676 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: vt: add permission check for KDSKBMETA ioctl KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process to change meta mode on a non-controlling console without authorization..

Description

In the Linux kernel, the following vulnerability has been resolved: vt: add permission check for KDSKBMETA ioctl KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process to change meta mode on a non-controlling console without authorization.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 9f8cbaf4b774694dcc292e60509762483ebfd9ae; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < ddc4a8303347114e945b9e6e81b81d77855f7358; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 1c5b67a1e2cb7d78dab321280f330b056e3bf437; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < d8ead5083b203d12b8319e7cb29cc6b8836e813f; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 4671c3b79e337bbae28c2d79023dc642df012bde; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < a1c31e026c93e378e297a8df8328983d3013a59f; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 7bf32337a7103ccb686cbd240324bf26225ef2d6; >= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < a7ad0034453ba4c353f9b8f810ee2569de33d283; < 5.10.265; < 5.15.216; < 6.1.183; < 6.6.152; < 6.12.104; < 6.18.45; < 7.1.9
LinuxLinuxAll versions

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-74676?
In the Linux kernel, the following vulnerability has been resolved: vt: add permission check for KDSKBMETA ioctl KDSKBMETA modifies keyboard meta mode but lacks the !perm check that all other keyboard setter ioctls in vt_k_ioctl() enforce, allowing a process to change meta mode on a non-controlling console without authorization.
How severe is CVE-2026-74676?
Severity scoring for CVE-2026-74676 is pending analysis.
How do I fix CVE-2026-74676?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-74676?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST