ima: fix out-of-bounds read in xattr_verify()

Summary

CVECVE-2026-74671
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-22 16:16:41 UTC
Updated2026-08-22 16:16:41 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ima: fix out-of-bounds read in xattr_verify() The digest-length check in xattr_verify() mixes int and size_t: if (xattr_len - sizeof(xattr_value->type) - hash_start >= iint->ima_hash->length) sizeof() yields size_t, so the usual arithmetic conversions promote the whole left-hand side to unsigned 64-bit before the subtraction runs. For a truncated xattr this underflows instead of going negative: a 1-byte IMA_XATTR_DIGEST_NG xattr (xattr_len == 1, hash_start == 1) turns "1 - 1 - 1" into SIZE_MAX, which is trivially >= ima_hash->length. The check then passes and the following memcmp() reads iint->ima_hash->length bytes starting past the end of the buffer vfs_getxattr_alloc() allocated for it. Nothing upstream clamps xattr_len back into a safe range first: ima_get_hash_algo() only special-cases xattr_len < 2 to pick a default algorithm, and evm_verifyxattr() returns INTEGRITY_UNKNOWN rather than failing when no HMAC key is loaded, so a truncated security.ima value reaches the length check as-is. Rewrite the comparison so every operand stays a signed int and no implicit conversion to size_t can occur.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d d823b5f4557083d1dd92096f796a78a2b1b06d10 git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d caeb105c15ea2431fa8da7ecfa242d0c68272426 git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d a784b4732ac7e51862b9b210c2d8b2ab9e83568c git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d b6cb134707a2127d90a58d69dd818679cae8033c git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d 7e515b6c9aab452a4f0734bd7208e4e780e164ca git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d 27f3924061592d0ef6b04e16f48754b6cb6adf27 git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d dd04114af0d451091f7b8cbd26d9e37d011e9131 git Not specified
CNA Linux Linux affected 3ea7a56067e663278470c04fd655adf809e72d4d 5ff232d31106f45ac87c3b64e1d35a0667777797 git Not specified
CNA Linux Linux affected 3.13 Not specified
CNA Linux Linux unaffected 3.13 semver Not specified
CNA Linux Linux unaffected 5.10.265 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.216 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.183 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.152 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.104 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.45 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.9 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/5ff232d31106f45ac87c3b64e1d35a0667777797 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b6cb134707a2127d90a58d69dd818679cae8033c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/caeb105c15ea2431fa8da7ecfa242d0c68272426 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a784b4732ac7e51862b9b210c2d8b2ab9e83568c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7e515b6c9aab452a4f0734bd7208e4e780e164ca 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d823b5f4557083d1dd92096f796a78a2b1b06d10 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dd04114af0d451091f7b8cbd26d9e37d011e9131 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/27f3924061592d0ef6b04e16f48754b6cb6adf27 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report