{"id":"CVE-2026-74470","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74470","summary":"scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write\n\nresp_report_zones() sizes the reply buffer from the CDB allocation\nlength. The v3 fix rounds alloc_len up with ALIGN() before deriving the\ndescriptor count:\n\n\trep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -\n\t\t\t RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);\n\tarr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);\n\nFor alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to\n0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit\nand truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which\npasses the !arr check, and desc = arr + 64 is then dereferenced in the\nloop -> out-of-bounds write / panic.\n\nClamp rep_max_zones to devip->nr_zones. The loop already stops at\nsdebug_capacity (after nr_zones zones), so a report can never hold more\nthan nr_zones descriptors; the clamp does not change the report, it only\nbounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device\nproperty that can never reach 0x100000000.","published":"2026-08-15T12:27:07.504Z","modified":"2026-08-17T03:47:34.801215850Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.151"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066"},{"type":"WEB","url":"https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74470.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74470"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T03:47:34.801215850Z"}}