CVE-2026-74361

critical

Description

In the Linux kernel, the following vulnerability has been resolved: nvme: fix FDP fdpcidx bounds check The fdpcidx bounds check sets n = NUMFDPC + 1 but used > instead of >=, incorrectly accepting fdp_idx when it equals n (i.e. NUMFDPC + 1).

References

https://git.kernel.org/stable/c/5e406928404d67a8da8aa3ae21732e1ea1a04118

https://git.kernel.org/stable/c/5d0e7d2af884b91329235abb16652ae4eead8079

https://git.kernel.org/stable/c/0967074f6830718fd2597404ef119bddd0dbfd00

Details

Source: Mitre, NVD

Published: 2026-08-15

Updated: 2026-08-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.00166