What is CVE-2026-74470?
CVE-2026-74470 is a vulnerability in the Linux kernel's scsi_debug module related to 'REPORT ZONES' command handling. An incorrect allocation length calculation can lead to an out-of-bounds (OOB) write, potentially allowing privilege escalation or system instability. Affected users should apply kernel updates immediately.
Azərbaycanca: CVE-2026-74470 Linux kernel-in scsi_debug modulunda 'REPORT ZONES' əmri işlənərkən yaranan zəiflikdir. Ayırma uzunluğunun (alloc_len) düzgün hesablanmaması səbəbindən bufer hüdudlarından kənar yazma (OOB write) baş verə bilər. Bu zəiflik zərərli istifadəçiyə imtiyazları artırmaq və ya sistemin dayanıqlığını pozmaq imkanı verə bilər; təsirlənən sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
In which Linux component was CVE-2026-74470 discovered?
CVE-2026-74470 was discovered in the scsi_debug module of the Linux kernel.
What outcomes can a malicious actor exploiting CVE-2026-74470 cause?
Exploiting CVE-2026-74470 can allow a malicious user to escalate privileges or cause system instability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.