CVE-2026-74470
Last modified
CVE-2026-74470 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic. Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= ebacb44cb2042b90951140eda806bedad23ef554, < 7b615fc139e35c81077046df44725c532f7e2404; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < 5d3e1d006bbb543259f9e31824caadbfff6a5465; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < 49e5b25a0b74dbac595f122e5608fdce2918cc4e; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < 495058429ca55ab7fcc21977b63b92907ad68066; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < 2047ed09bf13453b7d6f9431b112ec07984dd69b; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < d6e6da6bc3b53231fac77ffab428da8173ee729c; >= 7db0e0c8190a086ef92ce5bb960836cde49540aa, < 93dde0bf2f39a0f9f57fd610aa3201ce5b753433; c4d2d7c935a4ad20e8e726ca10499cefe4537103; >= 5.15.8, < 5.15.217; >= 5.10.85, < 5.11 |
| Linux | Linux | 5.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-74470?
How severe is CVE-2026-74470?
How do I fix CVE-2026-74470?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-74465In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74466In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74467In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74468In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74469In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-7447A flaw has been found in SourceCodester Pet Grooming Managem…6.3
- CVE-2026-74471In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-74472In the Linux kernel, the following vulnerability has been re…
- CVE-2026-74473In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-74474In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-74475In the Linux kernel, the following vulnerability has been re…10
- CVE-2026-74476In the Linux kernel, the following vulnerability has been re…9.1
Are you affected by CVE-2026-74470?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
