Description
In the Linux kernel, the following vulnerability has been resolved:

cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()

In cxl_cancel_auto_attach(), it assumes cxled->pos is a valid index for
accessing p->targets[]. However, cxled->pos can be set to negative errno
in cxl_region_sort_targets() if cxl_calc_interleave_pos() fails. This
causes the driver to use a negative index to access p->targets[],
resulting in out-of-bounds access.

Fix it by walking p->targets[] instead of using cxled->pos directly.
Published: 2026-08-15
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel a flaw in the CXL region driver allows an out‑of‑bounds array access when the driver assumes a valid target index. The index may be set to a negative error code during interleave calculation, causing the code to read through a kernel pointer. This memory corruption can lead to undefined behaviour, potentially enabling an attacker to modify kernel memory or crash the system. The weakness is a classic out‑of‑bounds read, which can be used to elevate privileges or crash services if an attacker can influence the values passed to the driver.

Affected Systems

The vulnerability resides in the generic Linux kernel CXL region driver. No specific kernel version range is listed in the CNA data, so any kernel build that includes the affected code path before the patch may be vulnerable.

Risk and Exploitability

The CVSS score is 8.4, indicating high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation under current conditions. Based on the description, it is inferred that the likely attack vector is local or privileged‑level, as exploitation would require local privilege or the ability to load and configure the driver. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, indicating that no public exploit has yet been seen, but the high CVSS score and kernel impact mean it remains a serious risk where an attacker can potentially gain elevated privileges or crash the system.

Generated by OpenCVE AI on August 22, 2026 at 03:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that updates cxl_cancel_auto_attach() to iterate over p->targets[] safely
  • Reboot the system after the kernel update to ensure the patch is active
  • Disable or unload the CXL driver if CXL functionality is not required, or restrict kernel module loading rights to privileged users

Generated by OpenCVE AI on August 22, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Mon, 17 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach() In cxl_cancel_auto_attach(), it assumes cxled->pos is a valid index for accessing p->targets[]. However, cxled->pos can be set to negative errno in cxl_region_sort_targets() if cxl_calc_interleave_pos() fails. This causes the driver to use a negative index to access p->targets[], resulting in out-of-bounds access. Fix it by walking p->targets[] instead of using cxled->pos directly.
Title cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:45:17.863Z

Reserved: 2026-08-15T05:44:03.879Z

Link: CVE-2026-74275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:26.897

Modified: 2026-08-17T06:19:21.187

Link: CVE-2026-74275

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74275 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T04:00:12Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input