CVE-2026-74729Disclosure

LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as both producer and consumer on the kfifo: it calls kfifo_skip() (advances out) and kfifo_put() (advances in) from the IRQ handler without synchronizing with snoop_file_read(), which also consumes via kfifo_to_user(). On SMP systems this concurrent access can leave (in - out) larger than the ring buffer, so __kfifo_to_user()'s clamp to (in - out) is ineffective and kfifo_copy_to_user() can attempt a copy_to_user() past the kmalloc-2k backing store: usercopy: Kernel memory exposure attempt detected from SLUB object 'kmalloc-2k' (offset 0, size 2049)! kernel BUG at mm/usercopy.c! Call trace: usercopy_abort __check_heap_object __check_object_size kfifo_copy_to_user __kfifo_to_user snoop_file_read vfs_read Serialize kfifo access with a per-channel spinlock shared between the IRQ handler (producer) and the file reader (consumer). Annotate @fifo with __guarded_by(&lock) and opt the driver into context analysis so the compiler enforces that all fifo access holds the lock.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-22: 3Patch / Workaround · 2026-08-22: 1Technical Details · 2026-08-22: 308-22
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-74729 Linux Kernel lpc-snoop Usercopy Overflow in snoop_file_read https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74729

    Post summary

    CVE‑2026‑74729 is reported as a Usercopy Overflow in the Linux kernel's lpc‑snoop snoop_file_read, with details hosted on a Vulmon vulnerability page.

    00001158
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-74729 In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as… https://www.cve.org/CVERecord?id=CVE-2026-74729 ----- Traducción: CVE-2026-74729 En … http://infoflow.cloud`

    Post summary

    CVE‑2026‑74729, a usercopy overflow in the Linux kernel’s aspeed lpc‑snoop module, has been fixed by a patch.

    0000027
    102 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74729 In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in snoop_file_read put_fifo_with_discard() acts as… https://www.cve.org/CVERecord?id=CVE-2026-74729

    Post summary

    The text announces that CVE-2026-74729, a usercopy overflow in the Linux kernel’s lpc-snoop module, has been resolved; no exploitation or PoC details are provided.

    00000949
    58.0K followersView on X

Explore more