-

CVE-2026-74703

vhost-scsi: Validate T10 PI scatterlist counts

In the Linux kernel, the following vulnerability has been resolved:

vhost-scsi: Validate T10 PI scatterlist counts

When T10 PI is negotiated, vhost-scsi splits protection bytes from
the data iterator before mapping the request scatterlists. A malformed
request can claim protection bytes that cover or exceed the full payload
length. The former leaves no data bytes to map, while the latter
underflows exp_data_len before advancing the iterator. Both cases can let
a zero data SGL count reach sg_alloc_table_chained(), which triggers
BUG_ON(!nents).

Reject protection lengths that cover or exceed the payload before
subtracting prot_bytes and advancing the iterator. Also propagate
negative errors from the protection SGL calculation before calling the
allocator, matching the data SGL path.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version bca939d5bcd00d6faea99c47eafd60bed573ef03
Version < 2417a498cf3fe64d06faf87e236eda98dd4f04e0
Status affected
Version bca939d5bcd00d6faea99c47eafd60bed573ef03
Version < f8fe3f8d342da750dd10361bf66009fd3072926b
Status affected
Version bca939d5bcd00d6faea99c47eafd60bed573ef03
Version < d876c493fc4b811941bfeb4c80beb2dfc4bf025e
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.15
Status affected
Version 0
Version < 6.15
Status unaffected
Version <= 6.18.*
Version 6.18.45
Status unaffected
Version <= 7.1.*
Version 7.1.9
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.11
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2417a498cf3fe64d06faf87e236eda98dd4f04e0
https://git.kernel.org/stable/c/d876c493fc4b811941bfeb4c80beb2dfc4bf025e
https://git.kernel.org/stable/c/f8fe3f8d342da750dd10361bf66009fd3072926b