Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-74278

Published Aug 15, 2026 EPSS 0.17% (6th pctl)

Overview

CVE-2026-74278 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Fix kernel heap address leak in bounce_error_event()

The comment above bounce_error_event() documents that user clients

should receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded

as variable-length data, while kernel clients should receive

SNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer.

However, the implementation unconditionally uses

SNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw

struct snd_seq_event pointer for all clients. When a bounce error

event is delivered to a USER_CLIENT via snd_seq_read(), the kernel

heap address in data.quote.event is exposed to userspace through

copy_to_user() in the fixed-length branch.

This is a distinct leak path from the one addressed by commit

705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read"),

which sanitizes data.ext.ptr in the variable-length branch of

snd_seq_read(). The bounce_error_event() leak uses fixed-l

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-74278?

CVE-2026-74278 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-74278?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-74278?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-74278?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-74278 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.