Improper access control in Linux kernel - CVE-2026-74580

 

Improper access control in Linux kernel - CVE-2026-74580

Published: August 24, 2026


Vulnerability identifier: #VU144981
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-74580
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to access memory outside the intended IOTLB-mapped region.

The vulnerability exists due to improper access control in the vhost vring metadata cache in drivers/vhost/vhost.c when reconfiguring vring addresses or vring size through vhost ioctls while a device IOTLB is attached. A local user can issue crafted vring reconfiguration ioctls after populating the metadata cache to access memory outside the intended IOTLB-mapped region.

The issue occurs because stale cached metadata mappings may continue to be used after live vring reconfiguration, causing subsequent used ring updates or descriptor fetches to use translations based on the old mapping.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-74580

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins