Linux kernel CVE announcements
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning
Date: Sun, 19 Jul 2026 17:39:35 +0200	[thread overview]
Message-ID: <2026071922-CVE-2026-64113-87d9@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ixgbevf: fix use-after-free in VEPA multicast source pruning

ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's
own address (VEPA multicast workaround) by freeing the skb and
continuing to the next descriptor:

    dev_kfree_skb_irq(skb);
    continue;

The skb pointer is declared outside the while loop and persists across
iterations.  Because the continue skips the "skb = NULL" reset at the
bottom of the loop, the next iteration enters the "else if (skb)" path
and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing
skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context.

The sibling driver iavf already handles this correctly by nulling the
pointer before continuing.  Apply the same pattern here.

I do not have ixgbevf hardware; the bug was found by static analysis
(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool
corroboration with the highest score in the scan).  The UAF was confirmed
under KASAN by loading a test module that reproduces the exact code
pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags):

  BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000
  Read of size 8 at addr 000000006163ae78 by task insmod/30
  freed 208-byte region [000000006163adc0, 000000006163ae90)

QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF
driver does not include the VEPA source pruning path, so a full
end-to-end reproduction with emulated hardware was not possible.

The Linux kernel CVE team has assigned CVE-2026-64113 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 5.10.258 with commit 3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 5.15.209 with commit 6ef30384a50a50e4a484cddf341bc27de31aa3de
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 6.1.175 with commit 55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 6.6.142 with commit add70e2682c0ad3be2a5810bcf1bc13963ba4df9
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 6.12.92 with commit a244395d8c563ed1bb26c3ef708db6aeeaa08084
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 6.18.34 with commit dfef79e09ed2f5df975c98547f97f5d7f8982a24
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 7.0.11 with commit e8768bcbe5cd30c4ea36a22022c9ffaa66903693
	Issue introduced in 3.19 with commit bad17234ba702a50aeec50ab04724ee58af89607 and fixed in 7.1 with commit 5d49b568c188dc77199d8d2b959c91da8cc27cf1

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64113
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/net/ethernet/intel/ixgbevf/ixgbevf_main.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb
	https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de
	https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1
	https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9
	https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084
	https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24
	https://git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693
	https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1

                 reply	other threads:[~2026-07-19 15:44 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026071922-CVE-2026-64113-87d9@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox