Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74498

Published Aug 15, 2026 EPSS 0.18% (7th pctl)

Overview

CVE-2026-74498 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set

When a USB audio endpoint requests full packet transfers via the fill_max

descriptor flag, data_ep_set_params() promotes ep->curpacksize to

ep->maxpacksize. However, maxsize is left at the original sample-rate

derived value.

Since u->buffer_size is allocated as maxsize * packets, the resulting

DMA buffer is far too small for the requested transfer length. When the

USB host controller streams up to curpacksize bytes per packet, it writes

past the end of the buffer via DMA, corrupting kernel heap memory.

Update maxsize to curpacksize when fill_max is set so that the allocated

DMA buffer size matches the actual transfer request size.

[ changed to reassign maxsize only when ep->fill_max is set -- tiwai ]

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74498?

CVE-2026-74498 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-74498?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74498?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74498?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74498 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.