CVE-2026-74741
CVE CVE-2026-74741EUVD EUVD-2026-66571Published 2026-08-26T14:36:52.000ZLast changed 2026-08-27T05:01:01.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: net: ngbe: fix NULL pointer dereference in non-MSI-X interrupt enabling In non-MSI-X mode (such as legacy INTx or single MSI), wx->msix_entry is not allocated or initialized. Calling NGBE_INTR_MISC(wx) dereferences wx->msix_entry->entry, leading to a NULL pointer dereference crash. This issue was introduced by fixing the IRQ vector when the number of VFs is 7. Fix the issue by explicitly checking `pdev->msix_enabled` to determine the correct vector index. Additionally, as a side fix, set the interrupt mask to BIT(0) for the non-MSI-X fallback. In MSI/INTx mode, the MISC and queue interrupts share vector 0, and the WX_PX_MISC_IVAR register is only valid in the MSI-X case. Thus, BIT(0) is the correct mask for the miscellaneous cause when MSI-X is disabled.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4174c0c331a2aa3322d3b3be532808deb041b37d <cef4c5b9aca24651d069adf9462b221df6a2a669; patch: 7.2; patch: 0; 6.16; patch: 6.18.46; 4174c0c331a2aa3322d3b3be532808deb041b37d <0ab482b2195edc000262f0eae1cdcb416b8f335d; 4174c0c331a2aa3322d3b3be532808deb041b37d <5f3a13e0bb5ebcc1ca2dfda42ea40b9f3c2be6ea; patch: 7.1.10
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.