LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-74356

Published
CVSS7.4
Severityhigh
Weakness—
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Description

In the Linux kernel, the following vulnerability has been resolved: vhost: fix vhost_get_avail_idx for a non empty ring vhost_get_avail_idx is supposed to report whether it has updated vq->avail_idx. Instead, it returns whether all entries have been consumed, which is usually the same. But not always - in drivers/vhost/net.c and when mergeable buffers have been enabled, the driver checks whether the combined entries are big enough to store an incoming packet. If not, the driver re-enables notifications with available entries still in the ring. The incorrect return value from vhost_get_avail_idx propagates through vhost_enable_notify and causes the host to livelock if the guest is not makin

References

← Back to the CVE Tracker

Our coverage of CVE-2026-74356

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-74356.