« Volver al listado

CVE-2026-74404

Estado: RecibidaAlta (7.8)—

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one

Sashiko notes:

> regarding the bounds check in snp_filter_reserved_mem_regions() > called via walk_iomem_res_desc(): does the check > if ((range_list->num_elements * 16 + 8) > PAGE_SIZE) > allow an off-by-one heap buffer overflow? > > If range_list->num_elements is 255, 255 * 16 + 8 = 4088, which is <= 4096. > Writing range->base (8 bytes) fills 4088-4095, but writing range->page_count > (4 bytes) would write to 4096-4099, overflowing the kzalloc-allocated > PAGE_SIZE buffer.

Leer descripción completaMostrar menos

Fix this by accounting for the entry about to be written to, in addition to the entries that are already allocated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Acceso local (AV:L) sin interacción (UI:N) con privilegios (PR:L) permite escalada mediante overflow de heap en kernel. El overflow en snp_filter_reserved_mem_regions() puede permitir ejecución de código o negación de servicio.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74404",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2",
              "lessThan": "830c1f3e71989448652973375ef5e39b6ede47a3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2",
              "lessThan": "c5c79d92da0f9a09f48be5e2aabed2d6d1a96294",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2",
              "lessThan": "af7341616b742ad2c374a90998bd650a035f694d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1ca5614b84eed5904f65f143e0e7aaab0ac4c6b2",
              "lessThan": "1b864b6cb213bbd7b406e9b2e98c962077f300df",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/crypto/ccp/sev-dev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.9"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.9",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/crypto/ccp/sev-dev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:42.433",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1b864b6cb213bbd7b406e9b2e98c962077f300df",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/830c1f3e71989448652973375ef5e39b6ede47a3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/af7341616b742ad2c374a90998bd650a035f694d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c5c79d92da0f9a09f48be5e2aabed2d6d1a96294",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one\n\nSashiko notes:\n\n> regarding the bounds check in snp_filter_reserved_mem_regions()\n> called via walk_iomem_res_desc(): does the check\n> if ((range_list->num_elements * 16 + 8) > PAGE_SIZE)\n> allow an off-by-one heap buffer overflow?\n>\n> If range_list->num_elements is 255, 255 * 16 + 8 = 4088, which is <= 4096.\n> Writing range->base (8 bytes) fills 4088-4095, but writing range->page_count\n> (4 bytes) would write to 4096-4099, overflowing the kzalloc-allocated\n> PAGE_SIZE buffer.\n\nFix this by accounting for the entry about to be written to, in addition to\nthe entries that are already allocated."
    }
  ],
  "lastModified": "2026-08-17T06:19:35.607",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}