« Volver al listado

CVE-2026-90079

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()

rvu_mbox_init() is called separately for AF-PF mailboxes during probe and for AF-VF mailboxes when SR-IOV is enabled. Each call used to allocate a new ng_rvu object, leaking the first allocation when the pointer was overwritten on the second call.

Sharing one ng_rvu across both paths exposed several teardown bugs: the error path freed all cn20k mailbox DMA and kfree()d ng_rvu even when only the failing init type should be unwound, leaving live AF-PF mailbox memory in use after an AF-VF init failure. mutex_init() was also re-run on the AF-VF path while AF-PF mailbox handlers could still hold rvu->mbox_lock.

Leer descripción completaMostrar menos

Probe and SR-IOV failure paths did not release cn20k mailbox DMA either, since cleanup only happened in rvu_remove().

Allocate ng_rvu once with devm_kzalloc(), initialize mbox_lock in the same block, unwind only the mailbox memory for the failing init type, and free cn20k mailbox DMA from the probe and pci_enable_sriov() error paths.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90079",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e53ee4acb220acab6832669334279367b0206af6",
              "lessThan": "a0fcbea79f034f49bdd44915f28938922023458d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e53ee4acb220acab6832669334279367b0206af6",
              "lessThan": "3b11a77f69980932c3924054d66e565c9a135747",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/af/cn20k/api.h",
            "drivers/net/ethernet/marvell/octeontx2/af/cn20k/mbox_init.c",
            "drivers/net/ethernet/marvell/octeontx2/af/rvu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/marvell/octeontx2/af/cn20k/api.h",
            "drivers/net/ethernet/marvell/octeontx2/af/cn20k/mbox_init.c",
            "drivers/net/ethernet/marvell/octeontx2/af/rvu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:57.210",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3b11a77f69980932c3924054d66e565c9a135747",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a0fcbea79f034f49bdd44915f28938922023458d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()\n\nrvu_mbox_init() is called separately for AF-PF mailboxes during probe\nand for AF-VF mailboxes when SR-IOV is enabled.  Each call used to\nallocate a new ng_rvu object, leaking the first allocation when the\npointer was overwritten on the second call.\n\nSharing one ng_rvu across both paths exposed several teardown bugs:\nthe error path freed all cn20k mailbox DMA and kfree()d ng_rvu even\nwhen only the failing init type should be unwound, leaving live AF-PF\nmailbox memory in use after an AF-VF init failure.  mutex_init() was\nalso re-run on the AF-VF path while AF-PF mailbox handlers could still\nhold rvu->mbox_lock.  Probe and SR-IOV failure paths did not release\ncn20k mailbox DMA either, since cleanup only happened in rvu_remove().\n\nAllocate ng_rvu once with devm_kzalloc(), initialize mbox_lock in the\nsame block, unwind only the mailbox memory for the failing init type,\nand free cn20k mailbox DMA from the probe and pci_enable_sriov()\nerror paths."
    }
  ],
  "lastModified": "2026-09-17T17:16:57.210",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}