CVE-2026-74712 | Linux Kernel up to 6.12.103/6.18.44/7.1.8 vdpa create_direct_keys out-of-bounds
A vulnerability was found in Linux Kernel up to 6.12.103/6.18.44/7.1.8. It has been declared as critical. Impacted is the function create_direct_keys of the component vdpa. Executing a manipulation can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-74712. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.