In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss with access_ok for uprobe_multi data As reported by… (CVE-2026-74258)
A vulnerability in the Linux kernel related to the BPF subsystem was resolved by adding a check with access_ok before using __get_user to access user-space data in uprobe_multi. This fix addresses improper validation of user-space data bounds, preventing potential unsafe memory access.
AI Analysis
Technical Summary
The Linux kernel contained a vulnerability in the BPF component where __get_user was used to access user-space data for uprobe_multi without first verifying the data bounds using access_ok. This could lead to unsafe memory access. The issue was reported by sashiko and resolved by guarding the __get_user access with access_ok to ensure proper validation of user-space data before access.
Potential Impact
Improper validation of user-space data bounds before accessing it could lead to memory safety issues within the kernel, potentially causing crashes or other unintended behavior. No specific exploitation details or impact severity are provided.
Mitigation Recommendations
A fix has been applied in the Linux kernel to guard __get_user access with access_ok for uprobe_multi data. Users should update to the fixed kernel versions once available. Patch status is not explicitly confirmed in the provided data; check the official Linux kernel advisories or repositories for the exact fixed versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: bpf: Guard __get_user acesss with access_ok for uprobe_multi data As reported by… (CVE-2026-74258)
Description
A vulnerability in the Linux kernel related to the BPF subsystem was resolved by adding a check with access_ok before using __get_user to access user-space data in uprobe_multi. This fix addresses improper validation of user-space data bounds, preventing potential unsafe memory access.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel contained a vulnerability in the BPF component where __get_user was used to access user-space data for uprobe_multi without first verifying the data bounds using access_ok. This could lead to unsafe memory access. The issue was reported by sashiko and resolved by guarding the __get_user access with access_ok to ensure proper validation of user-space data before access.
Potential Impact
Improper validation of user-space data bounds before accessing it could lead to memory safety issues within the kernel, potentially causing crashes or other unintended behavior. No specific exploitation details or impact severity are provided.
Mitigation Recommendations
A fix has been applied in the Linux kernel to guard __get_user access with access_ok for uprobe_multi data. Users should update to the fixed kernel versions once available. Patch status is not explicitly confirmed in the provided data; check the official Linux kernel advisories or repositories for the exact fixed versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-pwvf-7f5w-2qr5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-74258"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a808b6cbf8831d5394f7eec
Added to database: 08/15/2026, 15:53:16 UTC
Last enriched: 08/15/2026, 16:15:33 UTC
Last updated: 08/16/2026, 00:41:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.