CVE-2026-64113

Source
https://cve.org/CVERecord?id=CVE-2026-64113
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64113.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64113
Downstream
Published
2026-07-19T15:40:14.251Z
Modified
2026-07-21T03:47:56.767858886Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ixgbevf: fix use-after-free in VEPA multicast source pruning
Details

In the Linux kernel, the following vulnerability has been resolved:

ixgbevf: fix use-after-free in VEPA multicast source pruning

ixgbevfcleanrx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor:

dev_kfree_skb_irq(skb);
continue;

The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevfaddrxfrag() on the freed skb, dereferencing skbshinfo(skb)->nr_frags - a use-after-free in NAPI softirq context.

The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here.

I do not have ixgbevf hardware; the bug was found by static analysis (scandropcontinueloops.py + semgrep dropcontinueinloop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfreeskb, then read skbshinfo(skb)->nr_frags):

BUG: KASAN: slab-use-after-free in ixgbevfuaftest_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90)

QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64113.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bad17234ba702a50aeec50ab04724ee58af89607
Fixed
3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb
Fixed
6ef30384a50a50e4a484cddf341bc27de31aa3de
Fixed
55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1
Fixed
add70e2682c0ad3be2a5810bcf1bc13963ba4df9
Fixed
a244395d8c563ed1bb26c3ef708db6aeeaa08084
Fixed
dfef79e09ed2f5df975c98547f97f5d7f8982a24
Fixed
e8768bcbe5cd30c4ea36a22022c9ffaa66903693
Fixed
5d49b568c188dc77199d8d2b959c91da8cc27cf1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64113.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.19.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64113.json"