AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74275

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the cxl_cancel_auto_attach() function, which improperly assumes that the index cxled->pos is always valid for accessing the p->targets[] array. This flaw can lead to out-of-bounds access, potentially allowing an attacker to exploit the driver and cause instability or crashes. Organizations using affected versions of the Linux kernel, particularly those leveraging CXL (Compute Express Link) technology, should prioritize applying the fix to mitigate potential risks.

CVE
CVE-2026-74275
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() In cxl_cancel_auto_attach(), it assumes cxled->pos is a valid index for accessing p->targets[]. However, cxled->pos can be set to negative errno in cxl_region_sort_targets() if cxl_calc_interleave_pos() fails. This causes the driver to use a negative index to access p->targets[], resulting in out-of-bounds access. Fix it by walking p->targets[] instead of using cxled->pos directly.