CVE-2026-74380
Linux host1x GPU driver bug can cause kernel memory corruption
Is CVE-2026-74380 being exploited?
Not confirmed. CVE-2026-74380 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.13% probability of exploitation in the next 30 days.
How severe is CVE-2026-74380?
CVE-2026-74380 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74380?
Yes. A fix has been recorded for CVE-2026-74380. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74380 affect?
CVE-2026-74380 affects Linux kernel (host1x GPU driver), NVIDIA Tegra-based systems, Embedded/edge devices with host1x GPU. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74380?
Apply vendor kernel update or backport host1x iommu_map_sgtable/pin_job fix; restrict untrusted GPU access.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local or GPU-using process can trigger kernel memory corruption via incorrect iommu_map_sgtable handling, enabling privilege escalation or kernel crash (DoS).
Patch when possible
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < 5f3985c2a500df3126cb12a2e0ccf26a40bc495d
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < 3ac173e46ef6fda9c9df8d47cdff4df962df9728
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < 2a68928c445138961e2c451983b473aeb3f5b999
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < 79240eee5a40014d9edfabe19f06b35ffa84e5f8
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < e024c7993d839503d6c1f0044b8fc537c30300e9
- affected>= ad8f36e4b6b1c826a0daa5fda2c5839205b5aa8b and < 18f74762013a4b6aa6f905c4459e0f506f9c5c7b
- affected5.15
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.