Answer in brief
CVE-2026-74603 records a Unknown severity vulnerability in ptp: ocp: Fix board ID over-read. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <72ef3ce80078199bfad32f98d055f44ba7cd0c3d || >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <3d965811be78473654e6e8cc8e4fb7b6b87aa6c1 || >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <f92558bbe78d6284fedd053900f82a70f0aa8707 || >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <5fd91dd4a143479b0575fb1f202ec1c501e71fd5 || >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <f8d7e5751267637190eff887c971d5b468106213 || >=0cfcdd1ebcfe1a9b262f6ad8419580720dc843c4 <6b69f2ef10cdb018c0b127a7cab88e590bbddba4 | 72ef3ce80078199bfad32f98d055f44ba7cd0c3d, 3d965811be78473654e6e8cc8e4fb7b6b87aa6c1, f92558bbe78d6284fedd053900f82a70f0aa8707, 5fd91dd4a143479b0575fb1f202ec1c501e71fd5, f8d7e5751267637190eff887c971d5b468106213, 6b69f2ef10cdb018c0b127a7cab88e590bbddba4 |
| Linux/Linuxgeneric | 5.18 | Not reported |
Published upstream
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 22, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 22, 2026
In the Linux kernel, the following vulnerability has been resolved: ptp: ocp: Fix board ID over-read The EEPROM board ID is a fixed 13-byte field and is not guaranteed to contain a NUL terminator. Passing it directly to devlink_info_version_fixed_put() treats it as a C string and may read beyond the field. Format at most OCP_BOARD_ID_LEN bytes into the existing local buffer before reporting the ID. Use a precision limit because the snprintf() output size alone does not bound the source string scan.
Quoted source text, attributed separately from HOL analysis.