Out-of-bounds write in Linux kernel - CVE-2026-74384
Published: August 15, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in the nvme multipath namespace head flexible array member current_path[] when handling sparse NUMA node IDs during namespace path revalidation. A local user can trigger nvme multipath operations on a system with sparse NUMA node IDs to cause a denial of service.
Only systems using nvme multipath on architectures where NUMA node IDs are sparse are affected.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp (Ubuntu package)
How to mitigate CVE-2026-74384
linux (Ubuntu package) - addressed in versions 7.0.0-34.34, 7.0.0-34.34.1, 7.0.0-34.34~24.04.1, 7.0.0-1012.12~24.04.1, 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14, 7.0.0-1020.20
linux-gcp (Ubuntu package) - addressed in versions 7.0.0-1013.13, 7.0.0-1013.13~24.04.1, 7.0.0-1014.14
External References
- https://git.kernel.org/stable/c/001e57554de81aa79c25c18fd53911d8a415c304
- https://git.kernel.org/stable/c/140d6fff4ed266592492a23444043842b4af7a62
- https://git.kernel.org/stable/c/1d4131b5c9823c7d2c86389898ad1b466af7df5e
- https://git.kernel.org/stable/c/316b5f1168264844aa125959de1d6da2b1905795
- https://git.kernel.org/stable/c/7173a741fed73de6247384056fe92e582ba12507
- https://git.kernel.org/stable/c/7e7b167e65610dfa7564d449474f4b477f9d4c1c
- https://git.kernel.org/stable/c/9ffdd11bd6c961b46b3689850ff6c5d7af5c5fe5
- https://git.kernel.org/stable/c/bde4d6eb53f7d3cdae7e62c9ee84345fdd6e70a6