SCSI Sense Buffer Vulnerability in Linux Kernel by The Linux Foundation
CVE-2026-74557

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74557?

A vulnerability exists in the Linux kernel impacting the handling of SCSI sense data. The issue arises in the iscsi_scsi_cmd_rsp() function where the sense data is copied from a target-supplied data segment without proper bounds checking. When a target returns a SCSI Response with the data length equal to the sense length, a memcpy operation may read beyond the intended buffer, leading to stale data being introduced into the sense buffer. This situation can expose information that should not be accessible to userspace applications, thereby representing a potential security risk.

Affected Version(s)

Linux 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 < 7567f06abdefb1caf2d836107c4d08c5185c650e

Linux 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 < 60499924faf4ef97e84228c20515218ef121facf

Linux 7996a778ff8c717cb1a7a294475c59cc8f1e9fb8 < 3ef209ca0b4b68c75e9a814d90cc916026b5a6ac

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.