Vhost IoT Table Allocation Flaw in Linux Kernel
CVE-2026-74713

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-74713?

A memory allocation flaw exists in the vhost IOTLB component of the Linux Kernel that allows for improper handling of bound map allocations. The vulnerability arises when non-retiring IOTLB tables are allowed to allocate new entries even after reaching their specified limits. This can lead to resource exhaustion or improper handling of memory, making systems susceptible to maliciously crafted requests from userspace or guest-controlled environments. Implementing proper checks and corrections to allocation limits and handling of IOTLB entries can mitigate this risk.

Affected Version(s)

Linux 0bbe30668d89ec8a309f28ced6d092c90fb23e8c

Linux 0bbe30668d89ec8a309f28ced6d092c90fb23e8c < 1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94

Linux 5.7

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.