SB2026081570 - Out-of-bounds write in Linux kernel nvme host driver
Published: August 15, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-74384)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the nvme multipath namespace head flexible array member current_path[] when handling sparse NUMA node IDs during namespace path revalidation. A local user can trigger nvme multipath operations on a system with sparse NUMA node IDs to cause a denial of service.
Only systems using nvme multipath on architectures where NUMA node IDs are sparse are affected.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/001e57554de81aa79c25c18fd53911d8a415c304
- https://git.kernel.org/stable/c/140d6fff4ed266592492a23444043842b4af7a62
- https://git.kernel.org/stable/c/1d4131b5c9823c7d2c86389898ad1b466af7df5e
- https://git.kernel.org/stable/c/316b5f1168264844aa125959de1d6da2b1905795
- https://git.kernel.org/stable/c/7173a741fed73de6247384056fe92e582ba12507
- https://git.kernel.org/stable/c/7e7b167e65610dfa7564d449474f4b477f9d4c1c
- https://git.kernel.org/stable/c/9ffdd11bd6c961b46b3689850ff6c5d7af5c5fe5
- https://git.kernel.org/stable/c/bde4d6eb53f7d3cdae7e62c9ee84345fdd6e70a6