{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools  nvme_setup_descriptor_pools() indexes dev-\u003edescriptor_pools[] using the numa_node forwarded from hctx-\u003enuma_node by its single caller, nvme_init_hctx_common().  On a non-NUMA kernel hctx-\u003enuma_node is NUMA_NO_NODE (-1).  Because the parameter was declared 'unsigned', the value becomes UINT_MAX and the index walks off the array (sized to nr_node_ids), faulting during nvme_alloc_ns() and leaving the namespace without a /dev node.  Reproduces on any NVMe controller probed by a CONFIG_NUMA=n kernel:    BUG: unable to handle page fault for address: ffff889101603d38   RIP: 0010:nvme_init_hctx_common+0x5a/0x190 [nvme]   Call Trace:    nvme_init_hctx+0x10/0x20 [nvme]    nvme_alloc_ns+0x9e/0xa10 [nvme_core]    nvme_scan_ns+0x301/0x3b0 [nvme_core]    nvme_scan_ns_async+0x23/0x30 [nvme_core]  Switch the parameter to int and fall back to node 0 when it is NUMA_NO_NODE; node 0 is always present.",
  "id": "DEBIAN-CVE-2026-74383",
  "modified": "2026-09-14T16:47:39.901594332Z",
  "published": "2026-08-15T06:22:40.170Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-74383"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-74383"
  ]
}