CVE-2026-64118

Source
https://cve.org/CVERecord?id=CVE-2026-64118
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64118.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64118
Downstream
Published
2026-07-19T15:40:17.643Z
Modified
2026-07-22T05:29:59.349456308Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
qed: fix double free in qed_cxt_tables_alloc()
Details

In the Linux kernel, the following vulnerability has been resolved:

qed: fix double free in qedcxttables_alloc()

If one of the later PF or VF CID bitmap allocations fails, qedcidmapalloc() jumps to cidmapfail and frees the previously allocated CID bitmaps before returning an error. qedcxttablesalloc() then calls qedcxtmngrfree(), which invokes qedcidmapfree() again.

Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free.

The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3.

Runtime reproduction was not attempted because exercising the failing allocation path requires device-specific setup.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64118.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fe56b9e6a8d957d6a20729d626027f800c17a2da
Fixed
9fe030719bd083b766602692ee96c8c985798e3c
Fixed
06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227
Fixed
8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb
Fixed
3904b993cc17ec5d7c5d3b57dbd0b775dafb9684
Fixed
bdf678a273cadbccc347f331ae2e93ff4d14834c
Fixed
0e47fc1c9181ae029e0e35a865cbf2adcbae626c
Fixed
a04c207f0801abdd23a169b5f902a9845059a65a
Fixed
2bccfb8476ca5f3548afbd623dc7a6980d4e77de

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64118.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.142
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64118.json"