Shadowfetch Linux[verified]@ShadowfetchDisclosure
The post identifies CVE-2026-74578, explaining that AF_ALG can leak a live CTR IV if the 6.6.145 patch is not applied, indicating the patch mitigates the issue but providing no evidence of active exploitation or PoC.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The CVE details a race condition in Linux kernel AF_ALG skcipher async receive path that enables an unprivileged local attacker to overwrite the IV, causing keystream reuse and plaintext recovery.
CVE@CVEnewDisclosure
The post announces that CVE‑2026‑74578, a Linux kernel crypto issue, has been fixed, providing a brief technical description but no PoC, exploit code, or active exploitation evidence.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
This tweet is a brief notification linking to a vulnerability report for CVE-2026-74578, a kernel race condition that can leak plaintext, but it lacks details on PoC, exploitation, or mitigation.