CVE-2026-74312
CVE CVE-2026-74312EUVD EUVD-2026-59459Veröffentlicht 2026-08-15T05:58:11.000ZZuletzt geändert 2026-08-17T05:45:44.000ZCVSS 7.8
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: validate virtqueue index in mmap and fault paths vhost_vdpa_mmap() and vhost_vdpa_fault() use vma->vm_pgoff as a virtqueue index for get_vq_notification(), but they do not validate that the index is smaller than v->nvqs. The ioctl path already performs both a bounds check and array_index_nospec(), but the mmap/fault path only checks that the index fits in u16. This allows an out-of-range queue index to reach driver-specific get_vq_notification() callbacks. Fix this by extracting a unified vhost_vdpa_get_vq_notification() helper that validates the queue index against v->nvqs and applies array_index_nospec() before calling the driver callback. Both the mmap and fault paths use this helper, and the bounds checking is consolidated into a single location. From source inspection, the most defensible impact is out-of-bounds access in the callback path, potentially leading to invalid PFN remaps and crash/DoS.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <1f5f94c6c6b2e4eaa5b45815509e21d0c6cfa81e; patch: 6.18.40; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <bbba4f92515238d76018e9b75e41b16d83df52c8; patch: 5.10.261; patch: 5.15.212; patch: 6.1.178; 5.8; patch: 6.6.145; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <0f310bac6db9bd3bb1655707d692d9d2a86eeb17; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <32ac9097aa2463fcfc12f61cc4a9ebc3579cba7d; patch: 0; patch: 7.1.5; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <929e4f044621c8cc30b612fb74e1410bef09e41b; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <55a644031e610ea93fbde2702c7b8f267476552f; patch: 6.12.97; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <4bf5a51963ff816f7443702dc536b9327cf5e550; patch: 7.2; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <2b3f79b90b231a682315fe2191bb71925650e183
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.