{"id":"CVE-2026-74380","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74380","summary":"gpu: host1x: Fix iommu_map_sgtable() return value check","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix iommu_map_sgtable() return value check\n\nCommit \"iommu: return full error code from iommu_map_sg[_atomic]()\"\nchanged iommu_map_sgtable() to return an ssize_t and negative values\nin error cases, rather than a size_t and a zero.\n\npin_job() also was incorrectly assigning to 'int', which could cause\noverflows into negative values.\n\nUpdate pin_job() to correctly check for errors from iommu_map_sgtable.","published":"2026-08-15T05:58:57.706Z","modified":"2026-08-18T03:56:48.006768622Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.1.178"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/18f74762013a4b6aa6f905c4459e0f506f9c5c7b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2a68928c445138961e2c451983b473aeb3f5b999"},{"type":"WEB","url":"https://git.kernel.org/stable/c/3ac173e46ef6fda9c9df8d47cdff4df962df9728"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5f3985c2a500df3126cb12a2e0ccf26a40bc495d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/79240eee5a40014d9edfabe19f06b35ffa84e5f8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e024c7993d839503d6c1f0044b8fc537c30300e9"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74380.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74380"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:48.006768622Z"}}