CVE-2026-74694
CVE CVE-2026-74694EUVD EUVD-2026-64381Published 2026-08-22T15:32:57.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length ncsi_send_cmd_nl() takes the number of bytes to copy from the attacker-controlled ncsi_pkt_hdr.length field of the in-band packet header, while the source buffer is the NCSI_ATTR_DATA netlink attribute whose readable size is nla_len() - sizeof(ncsi_pkt_hdr). The two length sources are never cross-checked: only nla_len() >= sizeof(struct ncsi_pkt_hdr) is enforced. With hdr->length set larger than the attribute payload (up to 65535 against at most 2032 readable bytes), ncsi_cmd_handler_oem() copies past the end of the netlink attribute buffer with unsafe_memcpy(), leaking up to ~64KB of kernel heap memory into the transmitted NCSI command packet. The destination skb is sized by the declared payload, so the write side does not overflow - this is a pure OOB read / information leak, reachable with CAP_NET_ADMIN on systems with a registered NCSI device (e.g. OpenBMC on Aspeed BMC SoCs, where NET_NCSI=y is standard). Reject commands whose declared payload extends past the end of the data attribute. The issue was found by the autokbug dynamic kernel fuzzer at Tencent Yunding Lab.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <b5231ad0b376b801ab8cf2962b182cc29deaedb3; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <4489b4a17892750131e4bef4bc1d3d703c8fb5ba; patch: 7.1.9; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <67c72b8ef63d9d9a610546fda30b116638f39745; patch: 6.1.183; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <3a60b5af75abe8e3494ccd074fb4ae6e601a3e55; patch: 6.18.45; 4.20; patch: 0; patch: 5.15.216; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <43c7d0a6917751ea898ae584d00f24f5deac46d4; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <afa58b7384913c8773d837acdb07b035690ec5d2; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <e60afa01d35f8b2671b27ca93309921427144cce; 9771b8ccdfa6dcb1ac5128ca7fe8649f3092d392 <02226af69362758046822840fc6a497f5de33f00; patch: 5.10.265; patch: 6.12.104; patch: 7.2; patch: 6.6.152
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.