CVE-2026-64222

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2026
Last modified:
24/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> octeontx2-pf: avoid double free of pool-&gt;stack on AQ init failure<br /> <br /> otx2_pool_aq_init() frees pool-&gt;stack when mailbox sync or retry<br /> allocation fails, but leaves the pointer unchanged. Later,<br /> otx2_sq_aura_pool_init() unwinds the partial setup through<br /> otx2_aura_pool_free(), which frees pool-&gt;stack again. The CN20K-specific<br /> cn20k_pool_aq_init() implementation has the same bug in<br /> its corresponding error path.<br /> <br /> Set pool-&gt;stack to NULL immediately after the local free so the shared<br /> cleanup path does not free the same stack again while cleaning up<br /> partially initialized pool state.<br /> <br /> The bug was first flagged by an experimental analysis tool we are<br /> developing for kernel memory-management bugs while analyzing<br /> v6.13-rc1. The tool is still under development and is not yet publicly<br /> available. Manual inspection confirms that the bug is still present in<br /> v7.1-rc3.<br /> <br /> Runtime validation was not performed because reproducing this path<br /> requires OcteonTX2/CN20K hardware.

Impact