CVE-2026-74279

Source
https://cve.org/CVERecord?id=CVE-2026-74279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74279
Downstream
Published
2026-08-15T05:57:50.131Z
Modified
2026-08-18T03:56:56.667832267Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
crypto: cavium/cpt - fix DMA cleanup using wrong loop index
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: cavium/cpt - fix DMA cleanup using wrong loop index

The sg_cleanup error path used list[i] instead of list[j] when unmapping DMA buffers, leaking successfully mapped entries and repeatedly unmapping the failed one.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74279.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c694b233295b99c33dd5ac28aede9f171f5a6862
Fixed
23c6174e48f66fc10b998b0acdb406cb0caf5c80
Fixed
23d3a7e896a1fe2d7a6bcb42f093948b79f8a198
Fixed
28141f95ae93b18f9bfde953cb787fcb151fb9da
Fixed
8afd1007ef79898a6e010eaade97097e49405fce
Fixed
3b8a1e1f4e4071a62b20374028744e8cc8310d48
Fixed
fb4d57b83356d4bd411b45ede3024e0ff42c9b5e
Fixed
d319b83b97b3585550d9ae592dfa78c755b6129e
Fixed
9dbf173bd32d5f81b005008b682bfb50aa093455

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74279.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74279.json"