CVE-2026-64113 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.
A use-after-free vulnerability has been identified in the Linux kernel ixgbevf driver, specifically within the VEPA multicast source pruning process. This issue arises when the ixgbevf_clean_rx_irq() function frees a socket buffer (skb) after pruning frames based on the source MAC address. The skb pointer, which is declared outside the processing loop, retains its value across iterations. Consequently, the loop can inadvertently process a freed skb, leading to a use-after-free condition in the NAPI softirq context. This vulnerability has been confirmed using KASAN, which detected the use-after-free error pattern typical of memory corruption issues.
Users can apply the official patch available in the Linux kernel stable tree to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb | kernel.org | Patch |
| https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de | kernel.org | Patch |
| https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084 | kernel.org | Patch |
| https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.19, < 5.10.258 >= 5.11, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.142 >= 6.7, < 6.12.92 >= 6.13, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 12, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |