Junglewise Threat Intelligence

CVE-2026-64121: Linux Kernel slab-out-of-bounds read in IFB network driver

CVE-2026-64121 · Severity: info · CVSS 4.4 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Intermediate Functional Block (IFB) network driver. When a network device is configured with more receiving queues than transmitting queues, a system administrator requesting network statistics can trigger an out-of-bounds memory read. This could allow a local user with high privileges to view sensitive information from the system's memory that they should not have access to.

Technical details

A slab-out-of-bounds read exists in the Linux kernel's net/ifb driver. The `ifb_dev_init()` function allocates the `tx_private` array based on `dev->num_tx_queues`. However, the ethtool statistics callbacks (`ifb_get_ethtool_stats`, `ifb_get_strings`, and `ifb_get_sset_count`) incorrectly use `dev->real_num_rx_queues` and `dev->real_num_tx_queues` to iterate through these stats. In configurations where the number of RX queues exceeds the number of TX queues, the driver indexes past the allocated `tx_private` buffer. This allows a local attacker to leak adjacent slab data via the `ETHTOOL_GSTATS` ioctl. The issue has been patched by ensuring the driver consistently uses `dev->num_tx_queues` for all statistics operations.

Affected products

  • Linux Linux Kernel v7.1-rc2

Timeline

  • 2026-05-13: other: Patch authored
  • 2026-07-19: disclosed: CVE published

References

Related threats