Impact
In the Linux kernel, repeated calls to rvu_mbox_init caused a new ng_rvu object to be allocated each time, overwriting the previous pointer and leaking the first allocation. This oversight exposed several teardown bugs, including freeing all cn20k mailbox DMA and kfree()ing ng_rvu even when only the failing init type should be unwound. The result was that live AF‑PF mailbox memory remained in use after an AF‑VF init failure, and mutex reinitialization risked stale locks while handlers still held the mailbox lock. These issues can lead to a memory leak and potential use‑after‑free or kernel memory corruption, which could be exploited to cause denial of service or elevate privileges.
Affected Systems
The vulnerability affects the Linux kernel, specifically the octeontx2 driver that handles AF‑PF and AF‑VF mailboxes. No specific kernel version range is listed in the CNA data, so any kernel build that includes the older rvu_mbox_init logic before the fix is potentially vulnerable.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation in the wild. Nevertheless, because the flaw resides in kernel memory management and can cause use‑after‑free or stale lock states, a local attacker with sufficient privileges—such as through SR‑IOV management or AF‑VF initialization—could trigger a denial of service or achieve unauthorized privilege escalation. The vulnerability does not currently have a CVSS score in the supplied data, but the impact described suggests a severity that warrants timely mitigation.
OpenCVE Enrichment