qed: fix double free in qed_cxt_tables_alloc()
Summary
| CVE | CVE-2026-64118 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:53 UTC |
| Updated | 2026-07-19 16:17:53 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
qed: fix double free in qed_cxt_tables_alloc()
If one of the later PF or VF CID bitmap allocations fails,
qed_cid_map_alloc() jumps to cid_map_fail and frees the previously
allocated CID bitmaps before returning an error. qed_cxt_tables_alloc()
then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free()
again.
Fix this by setting each CID bitmap pointer to NULL after bitmap_free()
to avoid double free.
The bug was first flagged by an experimental analysis tool we are
developing for kernel memory-management bugs while analyzing
v6.13-rc1. The tool is still under development and is not yet publicly
available. Manual inspection confirms that the bug is still
present in v7.1-rc3.
Runtime reproduction was not attempted because exercising the failing
allocation path requires device-specific setup. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 9fe030719bd083b766602692ee96c8c985798e3c git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227 git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 3904b993cc17ec5d7c5d3b57dbd0b775dafb9684 git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da bdf678a273cadbccc347f331ae2e93ff4d14834c git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 0e47fc1c9181ae029e0e35a865cbf2adcbae626c git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da a04c207f0801abdd23a169b5f902a9845059a65a git |
Not specified |
| CNA |
Linux |
Linux |
affected fe56b9e6a8d957d6a20729d626027f800c17a2da 2bccfb8476ca5f3548afbd623dc7a6980d4e77de git |
Not specified |
| CNA |
Linux |
Linux |
affected 4.4 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 4.4 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.259 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.210 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.175 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/3904b993cc17ec5d7c5d3b57dbd0b775dafb9684 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/2bccfb8476ca5f3548afbd623dc7a6980d4e77de |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a04c207f0801abdd23a169b5f902a9845059a65a |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/bdf678a273cadbccc347f331ae2e93ff4d14834c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/9fe030719bd083b766602692ee96c8c985798e3c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0e47fc1c9181ae029e0e35a865cbf2adcbae626c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.