Junglewise Threat Intelligence

CVE-2026-63923: Linux Kernel Marvell OcteonTX2 OOB write in RVU mailbox handler

CVE-2026-63923 · Severity: info · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Marvell OcteonTX2 network driver. A local attacker with access to a Virtual Function (VF) could send specially crafted messages to the Administrative Function (AF) to cause memory corruption. This could lead to a system crash or potentially allow unauthorized access to kernel memory, impacting the overall stability and security of the host system.

Technical details

An out-of-bounds (OOB) write vulnerability exists in the rvu_mbox_handler_rep_event_notify() function within drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c. The handler fails to validate the 'pcifunc' field within the REP_EVENT_NOTIFY request body, which is controlled by the sender. When a Virtual Function (VF) is in switchdev representor mode, it can forward these messages to the Administrative Function (AF). The AF uses this unvalidated field to index the rvu->pf[] or rvu->hwvf[] arrays. For certain events like RVU_EVENT_MAC_ADDR_CHANGE, this results in a six-byte OOB write via ether_addr_copy(). The fix introduces a call to is_pf_func_valid() to ensure the pcifunc is within expected bounds before processing.

Affected products

  • Linux Linux Kernel 6.13, 7.1

Timeline

  • 2026-05-20: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats