Vhost IoT Table Allocation Flaw in Linux Kernel
CVE-2026-74713
Currently unrated
What is CVE-2026-74713?
A memory allocation flaw exists in the vhost IOTLB component of the Linux Kernel that allows for improper handling of bound map allocations. The vulnerability arises when non-retiring IOTLB tables are allowed to allocate new entries even after reaching their specified limits. This can lead to resource exhaustion or improper handling of memory, making systems susceptible to maliciously crafted requests from userspace or guest-controlled environments. Implementing proper checks and corrections to allocation limits and handling of IOTLB entries can mitigate this risk.
Affected Version(s)
Linux 0bbe30668d89ec8a309f28ced6d092c90fb23e8c
Linux 0bbe30668d89ec8a309f28ced6d092c90fb23e8c < 1ed35ac7f3fe2b4396bdd29ac3a7f0ebc0829e94
Linux 5.7