A vulnerability has been found in Linux Kernel up to 6.18.39/7.1.4 and classified as very critical. This affects the function
bpf_mprog_query of the component BPF cgroup backward compat. This manipulation of the argument uattr_size causes out-of-bounds write.
This vulnerability is tracked as CVE-2026-74371. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.