CVE-2026-64222 (GCVE-0-2026-64222)
Vulnerability from cvelistv5
Published
2026-07-24 15:23
Modified
2026-08-05 12:40
Summary
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the pointer unchanged. Later, otx2_sq_aura_pool_init() unwinds the partial setup through otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific cn20k_pool_aq_init() implementation has the same bug in its corresponding error path. Set pool->stack to NULL immediately after the local free so the shared cleanup path does not free the same stack again while cleaning up partially initialized pool state. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime validation was not performed because reproducing this path requires OcteonTX2/CN20K hardware.
Impacted products
Vendor Product Version
Linux Linux Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Version: caa2da34fd25a37e9fd43343b6966fb9d730a6d5
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/nic/cn20k.c",
            "drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "e6e9bc0bf963662b7042048ab0281014625d4cb4",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "b92e7ea408b6f1144648909c9c49a55d245d7300",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "94192b0579333c3deee2441379aab8ca98fc2e6b",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "4c29603498b05c049dbbbc47e882f2fbf0193cd7",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "0488a0bb344fb1992853b60082acff6be8164d74",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "0d9b9d7dbef976ae7f855b6358f1d703014e96ea",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            },
            {
              "lessThan": "9b244c242bec48b37e82b89787afd6a4c43457e1",
              "status": "affected",
              "version": "caa2da34fd25a37e9fd43343b6966fb9d730a6d5",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/nic/cn20k.c",
            "drivers/net/ethernet/marvell/octeontx2/nic/otx2_common.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "lessThan": "5.6",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.259",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.210",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.93",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.35",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.259",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.210",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.93",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.35",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.11",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "5.6",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: avoid double free of pool-\u003estack on AQ init failure\n\notx2_pool_aq_init() frees pool-\u003estack when mailbox sync or retry\nallocation fails, but leaves the pointer unchanged. Later,\notx2_sq_aura_pool_init() unwinds the partial setup through\notx2_aura_pool_free(), which frees pool-\u003estack again. The CN20K-specific\ncn20k_pool_aq_init() implementation has the same bug in\nits corresponding error path.\n\nSet pool-\u003estack to NULL immediately after the local free so the shared\ncleanup path does not free the same stack again while cleaning up\npartially initialized pool state.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2/CN20K hardware."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable initialization is reached through local netdevice operations such as RTM_SETLINK or ethtool reconfiguration, ultimately invoking ndo_open; received network packets do not directly reach it.\nAC:H - The attacker can fill the fixed mailbox by configuring many queues, but exploitation additionally requires an AF/NPA synchronization error or timeout. Legitimate mailbox users are serialized, so this failure is not reliably attacker-controlled.\nPR:L - CAP_NET_ADMIN is required in the device\u0027s owning network namespace. OcteonTX2 VFs can reasonably be delegated to a user-owned network namespace, where namespace-level administration suffices without initial-namespace root.\nUI:N - The attacker can initiate the interface-open or reconfiguration operation directly, without action by another user.\nS:U - The double free corrupts the kernel managing the affected PF or VF but does not inherently cross a VM, IOMMU, or separate security-authority boundary.\nC:H - The repeated release of coherent DMA pages can create overlapping allocations, while the stale qmem object can also be reclaimed and its DMA metadata influenced. This memory corruption can plausibly expose arbitrary kernel memory.\nI:H - Double-freeing DMA-backed pages can corrupt the page allocator and produce overlapping ownership, enabling arbitrary kernel-memory modification or control-flow hijacking.\nA:H - The double DMA/page release can immediately cause allocator warnings, an oops, or a kernel panic, and corrupted allocator state can crash the system later."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:40:09.522Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/e6e9bc0bf963662b7042048ab0281014625d4cb4"
        },
        {
          "url": "https://git.kernel.org/stable/c/b92e7ea408b6f1144648909c9c49a55d245d7300"
        },
        {
          "url": "https://git.kernel.org/stable/c/94192b0579333c3deee2441379aab8ca98fc2e6b"
        },
        {
          "url": "https://git.kernel.org/stable/c/4c29603498b05c049dbbbc47e882f2fbf0193cd7"
        },
        {
          "url": "https://git.kernel.org/stable/c/0488a0bb344fb1992853b60082acff6be8164d74"
        },
        {
          "url": "https://git.kernel.org/stable/c/0d9b9d7dbef976ae7f855b6358f1d703014e96ea"
        },
        {
          "url": "https://git.kernel.org/stable/c/c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec"
        },
        {
          "url": "https://git.kernel.org/stable/c/9b244c242bec48b37e82b89787afd6a4c43457e1"
        }
      ],
      "title": "octeontx2-pf: avoid double free of pool-\u003estack on AQ init failure",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64222",
    "datePublished": "2026-07-24T15:23:08.072Z",
    "dateReserved": "2026-07-19T15:36:31.770Z",
    "dateUpdated": "2026-08-05T12:40:09.522Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…