CVE-2026-74527
SR-IOV VF can overwrite CGX PKIND state on OcteonTX2, altering packet parsing
Is CVE-2026-74527 being exploited?
Not confirmed. CVE-2026-74527 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.12% probability of exploitation in the next 30 days.
How severe is CVE-2026-74527?
CVE-2026-74527 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-74527?
Yes. A fix has been recorded for CVE-2026-74527. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-74527 affect?
CVE-2026-74527 affects Linux kernel (octeontx2 driver), Marvell/OcteonTX2 CGX/NIX/rVU drivers, SR-IOV VF/PF on OcteonTX2 NICs. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-74527?
Apply vendor/kernel security update; restrict or disable SR-IOV VFs until patched
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A malicious VF can change hardware packet parsing (PKIND), causing misclassification, bypassing filters, intercepting or disrupting PF/VF traffic, or DoS.
Patch when possible
- affected>= 94d942c5fb970ac2166216838b278613decfa9a0 and < d3c6b0f48f126a36955b3fb4154a59d0b3621d97
- affected>= 94d942c5fb970ac2166216838b278613decfa9a0 and < 3bd438a58e910db5dc369aa25dfed1fc95f1b596
- affected4.20
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.