CVE-2026-74627

Source
https://cve.org/CVERecord?id=CVE-2026-74627
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74627.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74627
Downstream
Published
2026-08-22T15:32:09.405Z
Modified
2026-08-27T11:30:48.264708410Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
net: devmem: prevent net-iov / page mixing
Details

In the Linux kernel, the following vulnerability has been resolved:

net: devmem: prevent net-iov / page mixing

We should either have netiov or page backed frags in a single skb, otherwise it blows up down the stack. Don't allow mixing in zerocopyfillskbfrom_devmem().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74627.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bd61848900bff597764238f3a8ec67c815cd316e
Fixed
e9bfe12b1d04c34c6fedcba21d9709b65c08aa33
Fixed
ed08011ae0be88f16cceae190535d6c790c83b0c
Fixed
53a43508ee332d8bffe40590c3d189c92a551f9f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74627.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74627.json"