Junglewise Threat Intelligence

CVE-2026-74689: Linux kernel slab-out-of-bounds read in vcc_setsockopt()

CVE-2026-74689 · Severity: high · CVSS 7.1 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's ATM (Asynchronous Transfer Mode) networking subsystem contains a memory safety bug in the vcc_setsockopt() function that can be exploited to read data outside the allocated buffer. An attacker with network access or local access to the system can trigger this vulnerability by passing specially crafted socket options, potentially exposing sensitive kernel memory or causing a denial of service.

Technical details

The vulnerability is a slab-out-of-bounds read in net/atm/common.c's vcc_setsockopt() function, caused by an ineffective length validation check. The original code used a logical AND operator that short-circuited when __SO_LEVEL_MATCH() returned false, bypassing the optlen validation entirely. Additionally, even with proper level matching, a cgroup BPF setsockopt filter could shrink optlen after validation, causing copy_from_sockptr() to copy beyond the provided buffer size. The fix replaces copy_from_sockptr() with copy_safe_from_sockptr(), which unconditionally validates that optlen meets minimum requirements before copying. The vulnerability requires socket access (local or network-reachable depending on privilege level) and is exploitable by passing mismatched socket levels or relying on BPF filter interference.

Affected products

  • Linux Linux kernel Multiple versions prior to fix (commit d0c80dbb970439bd2eeb0e5effff8c16a5f4e1e3)

Timeline

  • 2026-08-22: disclosed: Published on NVD
  • 2026-08-05: patched: Fix committed by Eric Dumazet; backported to stable kernels

References

Related threats