{"api_version":"1","generated_at":"2026-08-22T17:47:29+00:00","cve":"CVE-2026-74495","urls":{"html":"https://cve.report/CVE-2026-74495","api":"https://cve.report/api/cve/CVE-2026-74495.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74495","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74495"},"summary":{"title":"igbvf: Fix leak in TX DMA error cleanup","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 13:17:54","updated_at":"2026-08-19 17:21:06"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c","name":"https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65","name":"https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad","name":"https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e","name":"https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04","name":"https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc","name":"https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293","name":"https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249","name":"https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74495","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74495","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 e42b7225c45f57b42306b80cdd3bda202bae7293 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 e3ed89c257f6361f13df23023cd10ace830330ad git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 56726ff12cb6759ab90d6f5332c2377aeca7d249 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 31089f4eab42e0fc248ec80c26f9b0bad59ba4cc git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 bc25d56c03e41c10bc4b40e99ca5d7b941675c04 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 845a9cdd9b03b7b6fa8de3ee80579780350a7f65 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 df07003b5a6c6c9fce60d765d6a3da815a74c41c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c1fa347f20f17f14a4a1575727fa24340e8a9117 0565052b7e2f436b7f1541f4849da96dc0aa7a0e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.33","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.33 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.265 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.216 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.183 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.151 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.103 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.44 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.8 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74495","cve":"CVE-2026-74495","epss":"0.004570000","percentile":"0.380590000","score_date":"2026-08-19","updated_at":"2026-08-20 00:13:08"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/net/ethernet/intel/igbvf/netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"e42b7225c45f57b42306b80cdd3bda202bae7293","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"e3ed89c257f6361f13df23023cd10ace830330ad","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"56726ff12cb6759ab90d6f5332c2377aeca7d249","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"31089f4eab42e0fc248ec80c26f9b0bad59ba4cc","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"bc25d56c03e41c10bc4b40e99ca5d7b941675c04","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"845a9cdd9b03b7b6fa8de3ee80579780350a7f65","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"df07003b5a6c6c9fce60d765d6a3da815a74c41c","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"},{"lessThan":"0565052b7e2f436b7f1541f4849da96dc0aa7a0e","status":"affected","version":"c1fa347f20f17f14a4a1575727fa24340e8a9117","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/net/ethernet/intel/igbvf/netdev.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.33"},{"lessThan":"2.6.33","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.265","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.216","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.183","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.151","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.103","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.44","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.8","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.265","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.216","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.183","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.151","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.103","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.44","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.8","versionStartIncluding":"2.6.33","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"2.6.33","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:N - The bug is in the igbvf VF transmit path reached whenever egress skbs are queued, including fragmented replies or forwarded traffic from remote peers on SR-IOV cloud/tenant networks with internet-facing VFs.\nAC:L - No race is required; an attacker can repeatedly drive fragmented TX skbs and SWIOTLB/DMA-mapping pressure until skb_frag_dma_map fails after a successful head map, deterministically hitting the off-by-one dma_error cleanup.\nPR:N - Reaching ndo_start_xmit via normal sockets on the VF requires no kernel capabilities; co-tenant or internet-facing traffic can induce the leaky dma_error path without local credentials on the victim.\nUI:N - No victim interaction is needed beyond the VF carrying traffic; the leak occurs automatically in dma_error cleanup during transmit once mapping failure conditions are met.\nS:U - Impact is confined to the kernel/DMA resources of the guest or host running igbvf and does not by itself cross a hypervisor, IOMMU isolation, or separate security authority boundary.\nC:H - The error path frees the skb while its head DMA/IOMMU mapping remains in buffer_info, so freed pages can be reallocated while still mapped, enabling plausible kernel memory disclosure via stale DMA state.\nI:H - Reusing the descriptor slot without unmapping the leaked head mapping corrupts driver/IOMMU metadata and accumulates orphan mappings, a defensible path to driver heap corruption or write primitives.\nA:H - Each leaked TX DMA/IOMMU mapping consumes finite SWIOTLB/IOMMU resources; repeated triggering can exhaust mappings and break transmit or disable the VF entirely."}]}],"providerMetadata":{"dateUpdated":"2026-08-19T16:37:53.097Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/e42b7225c45f57b42306b80cdd3bda202bae7293"},{"url":"https://git.kernel.org/stable/c/e3ed89c257f6361f13df23023cd10ace830330ad"},{"url":"https://git.kernel.org/stable/c/56726ff12cb6759ab90d6f5332c2377aeca7d249"},{"url":"https://git.kernel.org/stable/c/31089f4eab42e0fc248ec80c26f9b0bad59ba4cc"},{"url":"https://git.kernel.org/stable/c/bc25d56c03e41c10bc4b40e99ca5d7b941675c04"},{"url":"https://git.kernel.org/stable/c/845a9cdd9b03b7b6fa8de3ee80579780350a7f65"},{"url":"https://git.kernel.org/stable/c/df07003b5a6c6c9fce60d765d6a3da815a74c41c"},{"url":"https://git.kernel.org/stable/c/0565052b7e2f436b7f1541f4849da96dc0aa7a0e"}],"title":"igbvf: Fix leak in TX DMA error cleanup","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74495","datePublished":"2026-08-15T12:27:23.229Z","dateReserved":"2026-08-15T05:44:03.906Z","dateUpdated":"2026-08-19T16:37:53.097Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 13:17:54","lastModifiedDate":"2026-08-19 17:21:06","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74495","Ordinal":"1","Title":"igbvf: Fix leak in TX DMA error cleanup","CVE":"CVE-2026-74495","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74495","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nigbvf: Fix leak in TX DMA error cleanup\n\nIf an error is encountered while mapping TX buffers, the driver should\nunmap any buffers already mapped for that skb.\n\nBecause count is incremented before each frag mapping, it will always\nmatch the correct number of unmappings needed when dma_error is reached.\nDecrementing count before the while loop in dma_error causes an\noff-by-one error. If any mapping was successful before an unsuccessful\nmapping, exactly one DMA mapping (the head) would leak.\n\nThis bug was introduced by a 2010 fix for an endless loop in dma_error.\nAll other affected drivers have already been fixed.","Type":"Description","Title":"igbvf: Fix leak in TX DMA error cleanup"}]}}}