PT-2026-82117 · Linux · Linux Kernel
CVE-2026-74737
·
Published
2026-08-26
·
Updated
2026-08-30
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the packet reception path where the MAC Port ID is extracted from the RX DMA Descriptor metadata. The helper function
cppi5 desc get tags ids() incorrectly assigns a 16-bit Source Tag to the port id variable, whereas only the lower 8-bits represent the actual MAC Port ID. The upper 8-bits are hardware-reserved and contain arbitrary values, leading to out-of-bound memory access and sporadic kernel crashes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel