Executive brief
The Linux kernel's liquidio network driver cached PCI device pointers without maintaining proper reference counts, creating a use-after-free vulnerability when handling virtual function reset requests. An attacker with control of a virtual machine could exploit this to crash the host kernel or potentially execute arbitrary code with kernel privileges.
Technical details
The vulnerability exists in the liquidio network driver's SR-IOV (Single Root I/O Virtualization) implementation. The PF (physical function) driver cached VF (virtual function) PCI device pointers in the dpiring_to_vfpcidev_lut[] array by iterating with pci_get_device(), but did not properly maintain reference counts—the iterator drops references on each iteration, making the cached pointers stale. Later, when handling OCTEON_VF_FLR_REQUEST (virtual function function-level reset), the driver dereferenced these invalid pointers. The fix replaces cached VF mapping with runtime PCI IOV lookups that properly validate and reference-count the VF devices before use, and correctly release references via pci_dev_put(). The vulnerability affects CN23XX-based liquidio devices and requires virtual function access to trigger.
Affected products
- Linux Linux kernel CN23XX liquidio driver (affected in 5.x through 6.x, patched commit 5c0e3ba4f500fd4314ceb42f07f16bc445156431
Timeline
- 2026-08-15: disclosed
- 2026-07-07: patched: Upstream fix commit 5c0e3ba4f500fd4314ceb42f07f16bc445156431