CVE-2026-74280
10.0Linux · Kernel
A DMA cleanup flaw in the Linux kernel Marvell Octeontx crypto driver can lead to memory leaks and unauthorized access to protected memory.
Executive summary
A critical memory management vulnerability in the Linux kernel Marvell Octeontx crypto driver could allow a privileged attacker to access protected system memory.
Vulnerability
The sg_cleanup path uses an incorrect loop index when unmapping DMA buffers, resulting in memory leaks and improper unmapping. This vulnerability requires a privileged local user to trigger the flaw.
Business impact
The ability for a privileged user to leak or access protected memory poses a severe threat to system confidentiality and integrity. With a CVSS score of 10.0, this vulnerability is considered critical, as it could facilitate the bypass of kernel security boundaries or the theft of sensitive cryptographic data.
Remediation
Immediate Action: Apply the vendor-provided kernel patch by updating to version 5.10.261, 5.15.212, 6.1.178, 6.6.145, or later.
Proactive Monitoring: Monitor for unusual system behavior or unauthorized attempts to access cryptographic resources or kernel memory.
Compensating Controls: Limit access to systems using the Marvell Octeontx driver to only the most trusted administrative users to reduce the attack surface.
Exploitation status
Public Exploit Available: Yes (per enrichment.public_pocs)
Analyst recommendation
Given the critical nature of this memory access flaw, immediate kernel updates are required. Organizations should ensure that all systems utilizing the Marvell Octeontx crypto driver are patched to the latest stable versions to prevent potential memory exploitation.