Vulnerability in Linux Kernel Affecting Stream ID Mapping for vDEVICEs
CVE-2026-74573

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74573?

In the Linux kernel, a flaw exists within the iommu/arm-smmu-v3-iommufd module. This vulnerability arises when a device with multiple streams is mapped, causing the system to mismanage Stream IDs. Specifically, the mapping process assumes that each device has only one Stream ID, leading to a potential failure in guest vSID invalidation and exposing the system to out-of-bounds read issues. To mitigate this, an enhancement has been introduced that requires verification of the number of streams before permitting the mapping of a vDEVICE. If the number of streams is not set to one, the operation will not proceed, thus improving the robustness of the system against potential crashes or unauthorized access.

Affected Version(s)

Linux d68beb276ba26cec47350a6d468e967673ee0c56 < 3808bab5d95ae79e333e11f6a73d178e084c645d

Linux d68beb276ba26cec47350a6d468e967673ee0c56 < 0acbc621341aca4eb94d9c2f43e1ab273ff088f0

Linux d68beb276ba26cec47350a6d468e967673ee0c56

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.