CVE-2026-74280

10.0

Linux · Kernel

A DMA cleanup flaw in the Linux kernel Marvell Octeontx crypto driver can lead to memory leaks and unauthorized access to protected memory.

Executive summary

A critical memory management vulnerability in the Linux kernel Marvell Octeontx crypto driver could allow a privileged attacker to access protected system memory.

Vulnerability

The sg_cleanup path uses an incorrect loop index when unmapping DMA buffers, resulting in memory leaks and improper unmapping. This vulnerability requires a privileged local user to trigger the flaw.

Business impact

The ability for a privileged user to leak or access protected memory poses a severe threat to system confidentiality and integrity. With a CVSS score of 10.0, this vulnerability is considered critical, as it could facilitate the bypass of kernel security boundaries or the theft of sensitive cryptographic data.

Remediation

Immediate Action: Apply the vendor-provided kernel patch by updating to version 5.10.261, 5.15.212, 6.1.178, 6.6.145, or later.

Proactive Monitoring: Monitor for unusual system behavior or unauthorized attempts to access cryptographic resources or kernel memory.

Compensating Controls: Limit access to systems using the Marvell Octeontx driver to only the most trusted administrative users to reduce the attack surface.

Exploitation status

Public Exploit Available: Yes (per enrichment.public_pocs)

Analyst recommendation

Given the critical nature of this memory access flaw, immediate kernel updates are required. Organizations should ensure that all systems utilizing the Marvell Octeontx crypto driver are patched to the latest stable versions to prevent potential memory exploitation.

More Linux CVEs