Junglewise Threat Intelligence

CVE-2026-72329: Linux kernel liquidio use-after-free in VF pci_dev lookup

CVE-2026-72329 · Severity: critical · CVSS 9.3 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's liquidio network driver cached PCI device pointers without maintaining proper reference counts, creating a use-after-free vulnerability when handling virtual function reset requests. An attacker with control of a virtual machine could exploit this to crash the host kernel or potentially execute arbitrary code with kernel privileges.

Technical details

The vulnerability exists in the liquidio network driver's SR-IOV (Single Root I/O Virtualization) implementation. The PF (physical function) driver cached VF (virtual function) PCI device pointers in the dpiring_to_vfpcidev_lut[] array by iterating with pci_get_device(), but did not properly maintain reference counts—the iterator drops references on each iteration, making the cached pointers stale. Later, when handling OCTEON_VF_FLR_REQUEST (virtual function function-level reset), the driver dereferenced these invalid pointers. The fix replaces cached VF mapping with runtime PCI IOV lookups that properly validate and reference-count the VF devices before use, and correctly release references via pci_dev_put(). The vulnerability affects CN23XX-based liquidio devices and requires virtual function access to trigger.

Affected products

  • Linux Linux kernel CN23XX liquidio driver (affected in 5.x through 6.x, patched commit 5c0e3ba4f500fd4314ceb42f07f16bc445156431

Timeline

  • 2026-08-15: disclosed
  • 2026-07-07: patched: Upstream fix commit 5c0e3ba4f500fd4314ceb42f07f16bc445156431

References

Related threats