CVE-2026-74312
CVE CVE-2026-74312EUVD EUVD-2026-59459Published 2026-08-15T05:58:11.000ZLast changed 2026-08-17T05:45:44.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: vhost/vdpa: validate virtqueue index in mmap and fault paths vhost_vdpa_mmap() and vhost_vdpa_fault() use vma->vm_pgoff as a virtqueue index for get_vq_notification(), but they do not validate that the index is smaller than v->nvqs. The ioctl path already performs both a bounds check and array_index_nospec(), but the mmap/fault path only checks that the index fits in u16. This allows an out-of-range queue index to reach driver-specific get_vq_notification() callbacks. Fix this by extracting a unified vhost_vdpa_get_vq_notification() helper that validates the queue index against v->nvqs and applies array_index_nospec() before calling the driver callback. Both the mmap and fault paths use this helper, and the bounds checking is consolidated into a single location. From source inspection, the most defensible impact is out-of-bounds access in the callback path, potentially leading to invalid PFN remaps and crash/DoS.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <1f5f94c6c6b2e4eaa5b45815509e21d0c6cfa81e; patch: 6.18.40; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <bbba4f92515238d76018e9b75e41b16d83df52c8; patch: 5.10.261; patch: 5.15.212; patch: 6.1.178; 5.8; patch: 6.6.145; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <0f310bac6db9bd3bb1655707d692d9d2a86eeb17; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <32ac9097aa2463fcfc12f61cc4a9ebc3579cba7d; patch: 0; patch: 7.1.5; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <929e4f044621c8cc30b612fb74e1410bef09e41b; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <55a644031e610ea93fbde2702c7b8f267476552f; patch: 6.12.97; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <4bf5a51963ff816f7443702dc536b9327cf5e550; patch: 7.2; ddd89d0a059d8e9740c75a97e0efe9bf07ee51f9 <2b3f79b90b231a682315fe2191bb71925650e183
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.