What is CVE-2026-74472?
A vulnerability in the Linux kernel's `ublk` driver where the `ublk_ctrl_add_dev()` function fails to reset kernel-owned `->state` and `->ublksrv_pid` fields after copying `dev_info` from userspace. This may lead to sensitive information leakage. To mitigate, systems should be updated with the latest kernel patches.
Azərbaycanca: Linux nüvəsində `ublk` sürücüsündə aşkar edilmiş boşluqdur. `ublk_ctrl_add_dev()` funksiyası istifadəçi məkanından (`userspace`) kopyalanan `dev_info` strukturunda nüvənin idarə etdiyi `->state` və `->ublksrv_pid` sahələrini sıfırlamadığı üçün məlumat sızmasına səbəb ola bilər. Təsirə məruz qalmamaq üçün sistemləri ən son nüvə yeniləmələri ilə təmin etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which driver in the Linux kernel is affected by CVE-2026-74472?
This vulnerability was discovered in the `ublk` driver.
What might be the consequence of CVE-2026-74472?
It may lead to information leakage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.