news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-74693

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.18%
Risk score
4.0
Published
2026-08-22
Status
Published

In the Linux kernel, the following vulnerability has been resolved: net: prestera: validate firmware header length prestera_fw_hdr_parse() reads the firmware header before checking that the firmware image contains that header. Reject images shorter than struct prestera_fw_header before decoding the magic and version fields. A flaw was found in the `prestera` network driver in the Linux kernel. The `prestera_fw_hdr_parse()` function reads the firmware header before checking that the firmware image contains the entire header. This oversight could allow a local attacker to provide a specially crafted, malformed firmware image, potentially leading to a denial of service (DoS) by causing the system to crash or become unstable.

Weaknesses

CWE-125

Coverage 1

Advisories and references