Improper input validation in Linux kernel - CVE-2026-74703
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in the vhost-scsi request handling logic when processing a malformed request with negotiated T10 PI protection bytes. A local user can send a specially crafted request to cause a denial of service.
The issue is triggered when protection bytes cover or exceed the expected payload length, allowing a zero data scatterlist count to reach a BUG_ON condition.