Description
In the Linux kernel, the following vulnerability has been resolved:

octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()

rvu_mbox_init() is called separately for AF-PF mailboxes during probe
and for AF-VF mailboxes when SR-IOV is enabled. Each call used to
allocate a new ng_rvu object, leaking the first allocation when the
pointer was overwritten on the second call.

Sharing one ng_rvu across both paths exposed several teardown bugs:
the error path freed all cn20k mailbox DMA and kfree()d ng_rvu even
when only the failing init type should be unwound, leaving live AF-PF
mailbox memory in use after an AF-VF init failure. mutex_init() was
also re-run on the AF-VF path while AF-PF mailbox handlers could still
hold rvu->mbox_lock. Probe and SR-IOV failure paths did not release
cn20k mailbox DMA either, since cleanup only happened in rvu_remove().

Allocate ng_rvu once with devm_kzalloc(), initialize mbox_lock in the
same block, unwind only the mailbox memory for the failing init type,
and free cn20k mailbox DMA from the probe and pci_enable_sriov()
error paths.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In the Linux kernel, repeated calls to rvu_mbox_init caused a new ng_rvu object to be allocated each time, overwriting the previous pointer and leaking the first allocation. This oversight exposed several teardown bugs, including freeing all cn20k mailbox DMA and kfree()ing ng_rvu even when only the failing init type should be unwound. The result was that live AF‑PF mailbox memory remained in use after an AF‑VF init failure, and mutex reinitialization risked stale locks while handlers still held the mailbox lock. These issues can lead to a memory leak and potential use‑after‑free or kernel memory corruption, which could be exploited to cause denial of service or elevate privileges.

Affected Systems

The vulnerability affects the Linux kernel, specifically the octeontx2 driver that handles AF‑PF and AF‑VF mailboxes. No specific kernel version range is listed in the CNA data, so any kernel build that includes the older rvu_mbox_init logic before the fix is potentially vulnerable.

Risk and Exploitability

The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. Nevertheless, because the flaw resides in kernel memory management and can cause use‑after‑free or stale lock states, a local attacker with sufficient privileges—such as through SR‑IOV management or AF‑VF initialization—could trigger a denial of service or achieve unauthorized privilege escalation. The vulnerability does not currently have a CVSS score in the supplied data, but the impact described suggests a severity that warrants timely mitigation.

Generated by OpenCVE AI on September 20, 2026 at 03:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel release that contains the octeontx2-af update, which allocates ng_rvu once via devm_kzalloc and properly cleans up DMA and locks on error.
  • If an update cannot be applied immediately, disable SR‑IOV or avoid repeated calls to rvu_mbox_init during system boot or driver probe.
  • Verify that the kernel module uses devm_kzalloc for ng_rvu and that error paths only release resources for the failing type, preventing use‑after‑free.

Generated by OpenCVE AI on September 20, 2026 at 03:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401
CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init() rvu_mbox_init() is called separately for AF-PF mailboxes during probe and for AF-VF mailboxes when SR-IOV is enabled. Each call used to allocate a new ng_rvu object, leaking the first allocation when the pointer was overwritten on the second call. Sharing one ng_rvu across both paths exposed several teardown bugs: the error path freed all cn20k mailbox DMA and kfree()d ng_rvu even when only the failing init type should be unwound, leaving live AF-PF mailbox memory in use after an AF-VF init failure. mutex_init() was also re-run on the AF-VF path while AF-PF mailbox handlers could still hold rvu->mbox_lock. Probe and SR-IOV failure paths did not release cn20k mailbox DMA either, since cleanup only happened in rvu_remove(). Allocate ng_rvu once with devm_kzalloc(), initialize mbox_lock in the same block, unwind only the mailbox memory for the failing init type, and free cn20k mailbox DMA from the probe and pci_enable_sriov() error paths.
Title octeontx2-af: fix cn20k mailbox lifetime on repeated rvu_mbox_init()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:57.541Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.210

Modified: 2026-09-17T17:16:57.210

Link: CVE-2026-90079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime

  • CWE-416

    Use After Free