{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "ebacb44cb2042b90951140eda806bedad23ef554"
            },
            {
              "fixed": "7b615fc139e35c81077046df44725c532f7e2404"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "7db0e0c8190a086ef92ce5bb960836cde49540aa"
            },
            {
              "fixed": "5d3e1d006bbb543259f9e31824caadbfff6a5465"
            },
            {
              "fixed": "49e5b25a0b74dbac595f122e5608fdce2918cc4e"
            },
            {
              "fixed": "495058429ca55ab7fcc21977b63b92907ad68066"
            },
            {
              "fixed": "2047ed09bf13453b7d6f9431b112ec07984dd69b"
            },
            {
              "fixed": "d6e6da6bc3b53231fac77ffab428da8173ee729c"
            },
            {
              "fixed": "93dde0bf2f39a0f9f57fd610aa3201ce5b753433"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "c4d2d7c935a4ad20e8e726ca10499cefe4537103"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.15.8"
            },
            {
              "fixed": "5.15.217"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        },
        {
          "events": [
            {
              "introduced": "5.10.85"
            },
            {
              "fixed": "5.11"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.15.217"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.183"
            },
            {
              "fixed": "6.6.151"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.12.103"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.18.44"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "7.1.8"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74470.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write\n\nresp_report_zones() sizes the reply buffer from the CDB allocation\nlength. The v3 fix rounds alloc_len up with ALIGN() before deriving the\ndescriptor count:\n\n\trep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -\n\t\t\t RZONES_DESC_HD) \u003e\u003e ilog2(RZONES_DESC_HD);\n\tarr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);\n\nFor alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to\n0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit\nand truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which\npasses the !arr check, and desc = arr + 64 is then dereferenced in the\nloop -\u003e out-of-bounds write / panic.\n\nClamp rep_max_zones to devip-\u003enr_zones. The loop already stops at\nsdebug_capacity (after nr_zones zones), so a report can never hold more\nthan nr_zones descriptors; the clamp does not change the report, it only\nbounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device\nproperty that can never reach 0x100000000.",
  "id": "CVE-2026-74470",
  "modified": "2026-08-25T03:51:49.582922249Z",
  "published": "2026-08-15T12:27:07.504Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/5d3e1d006bbb543259f9e31824caadbfff6a5465"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/7b615fc139e35c81077046df44725c532f7e2404"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74470.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74470"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write"
}