What is CVE-2026-74454?
The CVE-2026-74454 vulnerability in the Linux kernel's drm/vc4 driver involves vc4_overflow_mem_work() incorrectly writing the size of the entire bin buffer object to the BPOS register instead of the overflow slot size. This leads to incorrect overflow slot sizing during binner out-of-memory events. Applying a kernel update is recommended for affected systems.
Azərbaycanca: Linux kernel-in drm/vc4 sürücüsündə aşkarlanan CVE-2026-74454 zəifliyi vc4_overflow_mem_work() funksiyasında BPOS registrinə səhvən bütün bin buffer obyektinin ölçüsünün yazılması ilə bağlıdır. Bu, binner yaddaş çatışmazlığı zamanı overflow slot ölçüsünün düzgün təyin edilməməsinə səbəb olur. Təsirə məruz qalan sistemlərdə kernel yeniləməsinin tətbiqi tövsiyə olunur.
FAQ2
In which component of the Linux kernel was CVE-2026-74454 discovered?
The vulnerability was discovered in the drm/vc4 driver of the Linux kernel.
What issue does this vulnerability cause during a binner out-of-memory event?
It causes incorrect overflow slot sizing because vc4_overflow_mem_work() incorrectly writes the size of the entire bin buffer object to the BPOS register.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.