SB20260816221 - Off-by-one in Linux kernel intel igbvf driver
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Off-by-one (CVE-ID: CVE-2026-74495)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in the igbvf TX DMA error cleanup logic when handling TX buffer mapping errors. A local user can trigger a DMA mapping failure after one or more successful mappings to cause a denial of service.
The issue can leak exactly one DMA mapping for the packet head when a fragment mapping fails after earlier mappings succeed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e
- https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc
- https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65
- https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04
- https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c