๐Ÿ” CVE Alert

CVE-2026-74470

UNKNOWN 0.0

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic. Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7db0e0c8190a086ef92ce5bb960836cde49540aa < 49e5b25a0b74dbac595f122e5608fdce2918cc4e 7db0e0c8190a086ef92ce5bb960836cde49540aa < 495058429ca55ab7fcc21977b63b92907ad68066 7db0e0c8190a086ef92ce5bb960836cde49540aa < 2047ed09bf13453b7d6f9431b112ec07984dd69b 7db0e0c8190a086ef92ce5bb960836cde49540aa < d6e6da6bc3b53231fac77ffab428da8173ee729c 7db0e0c8190a086ef92ce5bb960836cde49540aa < 93dde0bf2f39a0f9f57fd610aa3201ce5b753433 c4d2d7c935a4ad20e8e726ca10499cefe4537103 ebacb44cb2042b90951140eda806bedad23ef554 5.10.85 < 5.11 5.15.8 < 5.16
Linux / Linux
5.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e git.kernel.org: https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066 git.kernel.org: https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b git.kernel.org: https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c git.kernel.org: https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433