Executive brief
A vulnerability was identified in the Linux kernel's Intel ixgbevf network driver. This driver is used for virtualized network interfaces on certain Intel hardware. An exploit could cause a system crash or instability (use-after-free) when processing specific network traffic, potentially impacting the availability of the host or virtual machine.
Technical details
A use-after-free (UAF) vulnerability exists in the ixgbevf_clean_rx_irq() function of the ixgbevf driver. When the driver prunes frames whose source MAC matches the Virtual Function's (VF) own address (a VEPA multicast workaround), it frees the socket buffer (skb) but fails to nullify the pointer before continuing the loop. On the subsequent iteration, the stale pointer is dereferenced in ixgbevf_add_rx_frag(), leading to a UAF in the NAPI softirq context. This was identified via static analysis and confirmed with KASAN. Patches have been released for multiple stable kernel branches to nullify the skb pointer after freeing.
Affected products
- Linux Linux Kernel ixgbevf driver versions using double buffered page based receives
Timeline
- 2026-05-15: disclosed: Patch submitted by Michael Bommarito
- 2026-06-01: patched: Committed to stable branches by Greg Kroah-Hartman
- 2026-07-19: advisory: CVE-2026-64113 published
References
- https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb
- https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1
- https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1
- https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de
- https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084
- https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9
- https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24