CVE EVIDENCE REVIEW
ReviewCriticalEvidence review

CVE-2026-74556 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP, REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU whose DataSegmentLength exceeds that buffer. The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its data segment (sense/response data) into conn->data via iscsi_t...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= a081c13e39b5c17052a7b46fafa61019c4c110ff < a51812842084fd390590ab8dc0431f10c73ddc56, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < a8f94cc9f0e5759252551be3a172960c57f21f54, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < f1a3a51fc5dba0e99532379665069f1700da6b44, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < c97b5265cc47775f77fd2a23d6bde0426997b233, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < 084af0253673425ce2ae62e3c7f74f0dd023711b, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < 72815741715bd41556dac5eeb068bf0f8af06ee7, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < c1dea15f819cded9b3faf58f8bec72323568b6e6, >= 2.6.29
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 9.8 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= a081c13e39b5c17052a7b46fafa61019c4c110ff < a51812842084fd390590ab8dc0431f10c73ddc56, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < a8f94cc9f0e5759252551be3a172960c57f21f54, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < f1a3a51fc5dba0e99532379665069f1700da6b44, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < c97b5265cc47775f77fd2a23d6bde0426997b233, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < 084af0253673425ce2ae62e3c7f74f0dd023711b, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < 72815741715bd41556dac5eeb068bf0f8af06ee7, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < b0aa3e8e2ab4ca92adb28a3ef41873b3363b8676, >= a081c13e39b5c17052a7b46fafa61019c4c110ff < c1dea15f819cded9b3faf58f8bec72323568b6e6, >= 2.6.29. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.

CVE-2026-74556 Remediation Guide | SECUFOCUS NOW