Executive brief
The Linux kernel's ixgbe network driver incorrectly configures transmit queue settings (XPS) for XDP (eXpress Data Path) queues on systems with 64 or more CPUs. This causes memory corruption and kernel warnings when loading XDP programs on Intel E610 adapters, potentially leading to denial of service or system instability.
Technical details
The vulnerability is a slab-out-of-bounds write in the ixgbe driver's XDP queue initialization path. The root cause is that netif_set_xps_queue() is called for XDP transmit queues, which are not exposed to the network device layer. On systems with ≥64 CPUs using E610 adapters, the device supports a maximum of 63 netdev queue pairs but 64 XDP queues, causing an index out-of-bounds condition. When the XDP program is loaded and netif_set_xps_queue() is called for the 64th XDP queue, a 4-byte write occurs beyond allocated slab memory. The attack vector requires local access to load XDP programs. The fix skips XPS configuration for XDP-only transmit queues.
Affected products
- Linux Linux kernel affected versions prior to CVE-2026-74317 fix
Timeline
- 2026-08-15: disclosed
- 2026-08-15: advisory