Junglewise Threat Intelligence

CVE-2026-74702: Linux kernel vhost-scsi feature change validation flaw

CVE-2026-74702 · Severity: high · CVSS 8.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's vhost-scsi subsystem, used for paravirtualized SCSI device emulation in virtual machines, does not properly validate feature negotiation after an endpoint is activated. An attacker with local access to the host could trigger a kernel panic by modifying SCSI protection features after device setup, disrupting virtualization services and affecting all running virtual machines on that host.

Technical details

The vhost-scsi module allocates command protection scatterlist arrays (prot_sgl) during endpoint initialization based on the VIRTIO_SCSI_F_T10_PI feature bit state. However, vhost_scsi_set_features() incorrectly allows subsequent feature bit changes after the endpoint is active, violating the virtio feature negotiation protocol. When T10-PI protection is enabled after setup, the I/O path uses the new feature bit while command pools retain NULL prot_sgl pointers. This causes sg_alloc_table_chained() to be called with a NULL first_chunk parameter and oversized nents (129 entries), triggering a BUG_ON assertion in sg_pool_index() that crashes the kernel. The fix rejects all feature changes except VHOST_F_LOG_ALL while an endpoint is active, forcing userspace to deactivate and reconfigure the endpoint to safely change features.

Affected products

  • Linux Linux kernel <UNKNOWN>

Timeline

  • 2026-08-22: disclosed

Related threats