AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-74403

UNKNOWN · CVSS N/A

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the crypto subsystem, specifically in the handling of page allocation failures within the TIO interface. If memory pressure causes the allocation function to return NULL, the system may erroneously dereference an invalid pointer, potentially leading to undefined behavior or system crashes. Organizations utilizing Linux systems, particularly those relying on the crypto capabilities, should prioritize addressing this issue to mitigate risks associated with memory management errors.

CVE
CVE-2026-74403
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Check for page allocation failure correctly in TIO Sashiko notes: > if __snp_alloc_firmware_pages() returns NULL under memory pressure, is it > safe to pass it directly to page_address()? > > On architectures without HASHED_PAGE_VIRTUAL, page_address(NULL) might > compute a deterministic but invalid, non-zero virtual address. The > subsequent if (tio_status) check would then evaluate to true, and > sev_tsm_init_locked() would dereference the invalid pointer. Indeed, page_address(NULL) will return non-NULL garbage here. Fix this by checking the page allocation itself for NULL, not the resulting virtual address.