CVE-2026-74466

Source
https://cve.org/CVERecord?id=CVE-2026-74466
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74466.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74466
Downstream
Published
2026-08-15T12:27:05.020Z
Modified
2026-08-18T03:31:00.911562073Z
Summary
s390/zcrypt: Close speculative mem read possibility
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Close speculative mem read possibility

The domain value is extracted from a given CCA or EP11 ioctl struct when a CPRB is about to be sent. Thus this is a user controlled value. Under some special conditions (custom device node used, administrative load) this value is used as an array index after bounds checking, but without speculation barrier.

Add the missing arrayindexnospec() call to prevent speculative execution where this domain value is used.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74466.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cfd68b33094e1a92249850ff3c3c92ae9112a541
Fixed
82b62eda68abfb7a33ac40f24b8c4128c2891148
Fixed
e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74466.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
7.1.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74466.json"