Linux Kernel vhost-scsi Vulnerability in Command Resource Management
CVE-2026-74702
What is CVE-2026-74702?
A vulnerability has been identified in the Linux kernel's vhost-scsi component, which allows feature changes to be accepted even after the endpoint is active. This situation can lead to inconsistencies in the command resources and the data-path state. Specifically, the issue arises when the VIRTIO_SCSI_F_T10_PI feature bit is enabled after the endpoint has been set up, resulting in a null protection scatterlist (prot_sgl). Consequently, any I/O requests that utilize this feature may fail, causing potential disruptions in operational integrity and leading to system instability. It is vital to ensure that userspace applications clear the endpoint before altering any negotiated features to maintain the reliability of the I/O operations.
Affected Version(s)
Linux bf2d650391be508dd8b5e188b65ed32300cf3489
Linux bf2d650391be508dd8b5e188b65ed32300cf3489 < 9a3eb77a612f9d158e4d27df43677a014e9cfa55
Linux bf2d650391be508dd8b5e188b65ed32300cf3489 < 42bc45df5905e2b7dccb72adaf7730f66cfbe03f