CVE-2026-74280

Source
https://cve.org/CVERecord?id=CVE-2026-74280
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74280.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74280
Downstream
Published
2026-08-15T05:57:50.809Z
Modified
2026-08-18T03:56:56.734096906Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: marvell/octeontx - fix DMA cleanup using wrong loop index

The sg_cleanup path used list[i] instead of list[j] when unmapping DMA buffers, leaking successfully mapped entries and repeatedly unmapping the failed one.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74280.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
10b4f09491bfeb0b298cb2f49df585510ee6189a
Fixed
97f150ba3e372256eabb93bd80c2cf3740077fb5
Fixed
8a0db9fad3c97e6447a92417cb95d7c55eaa9530
Fixed
8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf
Fixed
ed374dbc70c10c4a864414b3d9c257faec8fd485
Fixed
6c721a3e43344f8560ee4ef506fc1f72b4646dcd
Fixed
5f99a396f706afc749448659d1565991330e4f71
Fixed
acff30cfc0d72465b51b0bfdf019f1cb54e15314
Fixed
7891c64c0520519782470ba29bac8a5761e295d8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74280.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74280.json"