{"api_version":"1","generated_at":"2026-08-18T23:39:11+00:00","cve":"CVE-2026-74280","urls":{"html":"https://cve.report/CVE-2026-74280","api":"https://cve.report/api/cve/CVE-2026-74280.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74280","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74280"},"summary":{"title":"crypto: marvell/octeontx - fix DMA cleanup using wrong loop index","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: marvell/octeontx - fix DMA cleanup using wrong loop index\n\nThe sg_cleanup path used list[i] instead of list[j] when unmapping DMA\nbuffers, leaking successfully mapped entries and repeatedly unmapping\nthe failed one.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:27","updated_at":"2026-08-17 06:19:21"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"10","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"10","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":10,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/acff30cfc0d72465b51b0bfdf019f1cb54e15314","name":"https://git.kernel.org/stable/c/acff30cfc0d72465b51b0bfdf019f1cb54e15314","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8a0db9fad3c97e6447a92417cb95d7c55eaa9530","name":"https://git.kernel.org/stable/c/8a0db9fad3c97e6447a92417cb95d7c55eaa9530","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7891c64c0520519782470ba29bac8a5761e295d8","name":"https://git.kernel.org/stable/c/7891c64c0520519782470ba29bac8a5761e295d8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf","name":"https://git.kernel.org/stable/c/8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6c721a3e43344f8560ee4ef506fc1f72b4646dcd","name":"https://git.kernel.org/stable/c/6c721a3e43344f8560ee4ef506fc1f72b4646dcd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5f99a396f706afc749448659d1565991330e4f71","name":"https://git.kernel.org/stable/c/5f99a396f706afc749448659d1565991330e4f71","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ed374dbc70c10c4a864414b3d9c257faec8fd485","name":"https://git.kernel.org/stable/c/ed374dbc70c10c4a864414b3d9c257faec8fd485","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/97f150ba3e372256eabb93bd80c2cf3740077fb5","name":"https://git.kernel.org/stable/c/97f150ba3e372256eabb93bd80c2cf3740077fb5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74280","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74280","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 97f150ba3e372256eabb93bd80c2cf3740077fb5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 8a0db9fad3c97e6447a92417cb95d7c55eaa9530 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a ed374dbc70c10c4a864414b3d9c257faec8fd485 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 6c721a3e43344f8560ee4ef506fc1f72b4646dcd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 5f99a396f706afc749448659d1565991330e4f71 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a acff30cfc0d72465b51b0bfdf019f1cb54e15314 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 10b4f09491bfeb0b298cb2f49df585510ee6189a 7891c64c0520519782470ba29bac8a5761e295d8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.7","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74280","cve":"CVE-2026-74280","epss":"0.007040000","percentile":"0.502740000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:46"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"97f150ba3e372256eabb93bd80c2cf3740077fb5","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"8a0db9fad3c97e6447a92417cb95d7c55eaa9530","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"ed374dbc70c10c4a864414b3d9c257faec8fd485","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"6c721a3e43344f8560ee4ef506fc1f72b4646dcd","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"5f99a396f706afc749448659d1565991330e4f71","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"acff30cfc0d72465b51b0bfdf019f1cb54e15314","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"},{"lessThan":"7891c64c0520519782470ba29bac8a5761e295d8","status":"affected","version":"10b4f09491bfeb0b298cb2f49df585510ee6189a","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/crypto/marvell/octeontx/otx_cptvf_reqmgr.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.7"},{"lessThan":"5.7","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: marvell/octeontx - fix DMA cleanup using wrong loop index\n\nThe sg_cleanup path used list[i] instead of list[j] when unmapping DMA\nbuffers, leaking successfully mapped entries and repeatedly unmapping\nthe failed one."}],"metrics":[{"cvssV3_1":{"baseScore":10,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - On OcteonTX/Thunder network appliances, remote peers reach setup_sgio_components() through inbound IPsec ESP or kTLS decryption that offloads AEAD/skcipher to the Marvell CPT VF before any peer authentication.\nAC:L - An attacker can reliably force the buggy sg_cleanup path by submitting heavily fragmented scatter-gather crypto requests that exhaust DMA/IOMMU mappings, causing dma_map_single() to fail at index i>=1 while earlier entries remain mapped.\nPR:N - Inbound network decryption invokes CPT hardware offload without attacker credentials; no init-namespace root or CAP_NET_ADMIN is required on an already configured VPN/TLS endpoint to deliver ciphertext that reaches this driver.\nUI:N - Exploitation requires only automated kernel crypto processing of attacker-supplied ciphertext or AF_ALG requests; no victim mount, file open, or other interactive action is needed.\nS:C - The flaw leaks DMA_BIDIRECTIONAL IOMMU mappings for the CPT PCI device, crossing the intended DMA boundary between host memory and hardware crypto offload rather than staying within a single software security scope.\nC:H - Leaked bidirectional IOMMU mappings leave previously mapped pages device-readable after logical cleanup, enabling memory disclosure when stale mappings persist or interact with subsequent CPT DMA activity under resource pressure.\nI:H - Unreleased DMA_BIDIRECTIONAL mappings and repeated bogus dma_unmap_single() calls on the failed entry can corrupt IOMMU bookkeeping and allow the CPT device to perform unintended DMA writes to host memory outside the aborted request buffers.\nA:H - Each triggered failure leaks IOMMU mappings and may WARN or panic on invalid unmaps, causing gradual DMA resource exhaustion or immediate kernel crashes that deny crypto and overall system availability on affected OcteonTX systems."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:45:21.184Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/97f150ba3e372256eabb93bd80c2cf3740077fb5"},{"url":"https://git.kernel.org/stable/c/8a0db9fad3c97e6447a92417cb95d7c55eaa9530"},{"url":"https://git.kernel.org/stable/c/8d301e5a51173ba56ce4f632a2a33bf6b14b0fcf"},{"url":"https://git.kernel.org/stable/c/ed374dbc70c10c4a864414b3d9c257faec8fd485"},{"url":"https://git.kernel.org/stable/c/6c721a3e43344f8560ee4ef506fc1f72b4646dcd"},{"url":"https://git.kernel.org/stable/c/5f99a396f706afc749448659d1565991330e4f71"},{"url":"https://git.kernel.org/stable/c/acff30cfc0d72465b51b0bfdf019f1cb54e15314"},{"url":"https://git.kernel.org/stable/c/7891c64c0520519782470ba29bac8a5761e295d8"}],"title":"crypto: marvell/octeontx - fix DMA cleanup using wrong loop index","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74280","datePublished":"2026-08-15T05:57:50.809Z","dateReserved":"2026-08-15T05:44:03.880Z","dateUpdated":"2026-08-17T05:45:21.184Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:27","lastModifiedDate":"2026-08-17 06:19:21","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":10,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74280","Ordinal":"1","Title":"crypto: marvell/octeontx - fix DMA cleanup using wrong loop inde","CVE":"CVE-2026-74280","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74280","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: marvell/octeontx - fix DMA cleanup using wrong loop index\n\nThe sg_cleanup path used list[i] instead of list[j] when unmapping DMA\nbuffers, leaking successfully mapped entries and repeatedly unmapping\nthe failed one.","Type":"Description","Title":"crypto: marvell/octeontx - fix DMA cleanup using wrong loop inde"}]}}}