Linux Kernel vhost-scsi: T10 PI SGL count validation flaw
CVE-2026-74703 Published on August 22, 2026
vhost-scsi: Validate T10 PI scatterlist counts
In the Linux kernel, the following vulnerability has been resolved:
vhost-scsi: Validate T10 PI scatterlist counts
When T10 PI is negotiated, vhost-scsi splits protection bytes from
the data iterator before mapping the request scatterlists. A malformed
request can claim protection bytes that cover or exceed the full payload
length. The former leaves no data bytes to map, while the latter
underflows exp_data_len before advancing the iterator. Both cases can let
a zero data SGL count reach sg_alloc_table_chained(), which triggers
BUG_ON(!nents).
Reject protection lengths that cover or exceed the payload before
subtracting prot_bytes and advancing the iterator. Also propagate
negative errors from the protection SGL calculation before calling the
allocator, matching the data SGL path.
Products Associated with CVE-2026-74703
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version bca939d5bcd00d6faea99c47eafd60bed573ef03 and below 2417a498cf3fe64d06faf87e236eda98dd4f04e0 is affected.
- Version bca939d5bcd00d6faea99c47eafd60bed573ef03 and below f8fe3f8d342da750dd10361bf66009fd3072926b is affected.
- Version bca939d5bcd00d6faea99c47eafd60bed573ef03 and below d876c493fc4b811941bfeb4c80beb2dfc4bf025e is affected.
- Version 6.15 is affected.
- Before 6.15 is unaffected.
- Version 6.18.45, <= 6.18.* is unaffected.
- Version 7.1.9, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.