← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 22, 2026 · 16:16via CVEFeed

CVE-2026-74713 - vhost_iotlb: bound map allocation in add_range

Brief

CVE ID : CVE-2026-74713

Published : Aug. 22, 2026, 4:16 p. m.

  • 4 hours, 54 minutes ago

Description : In the Linux kernel, the following vulnerability has been resolved:

vhost_iotlb: bound map allocation in add_range

vhost_iotlb_add_range_ctx() only retires an old entry when the table has a non-zero limit, has exactly reached that limit and has VHOST_IOTLB_FLAG_RETIRE set. Non-retiring tables can keep allocating entries after reaching their configured limit.

Existing vhost devices allocate their IOTLB with max_iotlb_entries from vhost. c, which defaults to 2048 and is tunable by module parameter. Use the caller-provided limit at the allocation point instead of adding a separate default in the common IOTLB helper, and reject non-positive values in vhost paths that can report an error.

Read more on CVEFeed