ixgbevf: fix use-after-free in VEPA multicast source pruning

Summary

CVECVE-2026-64113
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:52 UTC
Updated2026-07-19 16:17:52 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 6ef30384a50a50e4a484cddf341bc27de31aa3de git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1 git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 add70e2682c0ad3be2a5810bcf1bc13963ba4df9 git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 a244395d8c563ed1bb26c3ef708db6aeeaa08084 git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 dfef79e09ed2f5df975c98547f97f5d7f8982a24 git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 e8768bcbe5cd30c4ea36a22022c9ffaa66903693 git Not specified
CNA Linux Linux affected bad17234ba702a50aeec50ab04724ee58af89607 5d49b568c188dc77199d8d2b959c91da8cc27cf1 git Not specified
CNA Linux Linux affected 3.19 Not specified
CNA Linux Linux unaffected 3.19 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report