CRITICAL Introduced in 6.14
vdpa IrqMap OOB
CVE-2026-74309
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
KernelScan AI8.7HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler Look up the IRQ index in oct_hw->irqs instead of assuming irq - irqs[0]. This supports non-contiguous IRQ numbers and avoids incorrect ring indexing when irqs[0] is not the base.
02KernelScan AI Analysis
Risk summary
A guest VM or container assigned a vDPA device backed by a Marvell Octeon endpoint can trigger out-of-bounds kernel memory access on the host when the system allocates non-contiguous IRQ numbers to the device. This can corrupt host kernel memory, potentially enabling a guest-to-host escape or host kernel crash. The vulnerability requires specific Octeon endpoint hardware and a vDPA deployment.
Vulnerability analysis
The interrupt handler in the Octeon endpoint vDPA driver incorrectly calculates which packet queue belongs to an incoming hardware interrupt by assuming all assigned interrupt numbers are contiguous. When the system allocates non-contiguous interrupts, this calculation produces an index outside the bounds of the queue table. The handler then reads from that invalid location and uses the result as a device memory address, which can corrupt host kernel state or crash the host. The fix corrects the mapping by searching the active interrupt table for the proper queue index and ignoring unrecognized interrupts, ensuring the handler only accesses valid queues. A guest virtual machine or container that has been assigned the device can trigger this path during normal network traffic, without needing special privileges.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| mainline | 6.14 | 7.2-rc1 | 0d21a1d6375a |
| 6.18 | 6.14 | 6.18.40 | 3ef0cfa77a3d |
| 7.1 | 6.14 | 7.1.5 | c6c7eae5de79 |