Out-of-bounds read in Linux kernel - CVE-2026-74737
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds memory access in the am65-cpsw-nuss packet reception path when processing RX DMA descriptor metadata containing the source tag. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue occurs because the driver uses the full 16-bit source tag as the port identifier even though only the lower 8 bits represent the MAC port ID, while the upper 8 bits are hardware-reserved and may contain arbitrary values.
Affected software
How to mitigate CVE-2026-74737
External References
- https://git.kernel.org/stable/c/14fc40bf28390e0ebee6a072457c36b82c614100
- https://git.kernel.org/stable/c/1c0e35ce761131f82062222779d8574849790892
- https://git.kernel.org/stable/c/36a05d2820077bb3955acb8111e1041d39148037
- https://git.kernel.org/stable/c/46a8e084a159e638ac2728e96980b65d752d65fd
- https://git.kernel.org/stable/c/551688b410d3fb0dae7739724422f268cd9446d6
- https://git.kernel.org/stable/c/72e4e3d7efc3b7d85f86abbe8b94f8e45074abe3
- https://git.kernel.org/stable/c/914e0100df3435bd14d09f397238e891cf9b7dce
- https://git.kernel.org/stable/c/9a220225efd6f58350bbb53fe70bdec08519267f