{"apiVersion":"1.0","identifier":"CVE-2026-74671","description":"In the Linux kernel, the following vulnerability has been resolved: ima: fix out-of-bounds read in xattr_verify() The digest-length check in xattr_verify() mixes int and size_t: if (xattr_len - sizeof(xattr_value->type) - hash_start >= iint->ima_hash->length) sizeof() yields size_t, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtraction runs. For a truncated xattr this underflows instead of going negative: a 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1) turns -1 - 1 - 1- into SIZE_MAX, which is trivially >= ima_hash->length. The check then passes and the following memcmp() reads iint->ima_hash->length bytes starting past the end of the buffer vfs_getxattr_alloc() allocated for it. Nothing upstream clamps xattr_len back into a safe range first: ima_get_hash_algo() only special-cases xattr_len < 2 to pick a default algorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than failing when no HMAC key is loaded, so a truncated security.ima value reaches the length check as-is. Rewrite the comparison so every operand stays a signed int and no implicit conversion to size_t can occur.","publishedAt":"2026-08-22T16:16:41","lastModifiedAt":"2026-08-22T16:16:41","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74671","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00177,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74671","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74671","en":"https://www.redsauce.net/en/cves/CVE-2026-74671","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74671","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74671","de":"https://www.redsauce.net/de/cves/CVE-2026-74671","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74671","el":"https://www.redsauce.net/el/cves/CVE-2026-74671"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74671"}}