Junglewise Threat Intelligence

CVE-2026-64224: Linux Kernel double free in octeontx2-pf rvu_rep_rsrc_init

CVE-2026-64224 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's network driver for Marvell OcteonTX2 hardware. The issue occurs during the initialization of network resources, where a specific failure could cause the system to attempt to release the same memory twice. This type of memory management error can lead to system instability or crashes, potentially impacting the availability of servers using this specific networking hardware.

Technical details

A double-free vulnerability exists in the Linux kernel's Marvell OcteonTX2 Physical Function (PF) driver within the 'rvu_rep_rsrc_init' function. The root cause is improper error handling: when 'otx2_init_hw_resources' fails, it performs its own cleanup of hardware resources (SQ, CQ, and aura state), but the caller's error path subsequently calls 'otx2_free_hw_resources', leading to a second free of the same resources. This is a local vulnerability requiring specific hardware configurations to trigger. The fix involves refactoring the cleanup labels to ensure that hardware resources are only freed once during an initialization failure. Patches have been merged into the stable kernel tree.

Affected products

  • Linux Linux Kernel v6.13 to v7.1-rc3

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats