Linux Kernel vhost-scsi Vulnerability in Command Resource Management
CVE-2026-74702

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74702?

A vulnerability has been identified in the Linux kernel's vhost-scsi component, which allows feature changes to be accepted even after the endpoint is active. This situation can lead to inconsistencies in the command resources and the data-path state. Specifically, the issue arises when the VIRTIO_SCSI_F_T10_PI feature bit is enabled after the endpoint has been set up, resulting in a null protection scatterlist (prot_sgl). Consequently, any I/O requests that utilize this feature may fail, causing potential disruptions in operational integrity and leading to system instability. It is vital to ensure that userspace applications clear the endpoint before altering any negotiated features to maintain the reliability of the I/O operations.

Affected Version(s)

Linux bf2d650391be508dd8b5e188b65ed32300cf3489

Linux bf2d650391be508dd8b5e188b65ed32300cf3489 < 9a3eb77a612f9d158e4d27df43677a014e9cfa55

Linux bf2d650391be508dd8b5e188b65ed32300cf3489 < 42bc45df5905e2b7dccb72adaf7730f66cfbe03f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.