{"id":"CVE-2026-64113","summary":"ixgbevf: fix use-after-free in VEPA multicast source pruning","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nixgbevf: fix use-after-free in VEPA multicast source pruning\n\nixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's\nown address (VEPA multicast workaround) by freeing the skb and\ncontinuing to the next descriptor:\n\n    dev_kfree_skb_irq(skb);\n    continue;\n\nThe skb pointer is declared outside the while loop and persists across\niterations.  Because the continue skips the \"skb = NULL\" reset at the\nbottom of the loop, the next iteration enters the \"else if (skb)\" path\nand calls ixgbevf_add_rx_frag() on the freed skb, dereferencing\nskb_shinfo(skb)-\u003enr_frags - a use-after-free in NAPI softirq context.\n\nThe sibling driver iavf already handles this correctly by nulling the\npointer before continuing.  Apply the same pattern here.\n\nI do not have ixgbevf hardware; the bug was found by static analysis\n(scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool\ncorroboration with the highest score in the scan).  The UAF was confirmed\nunder KASAN by loading a test module that reproduces the exact code\npattern (alloc skb, kfree_skb, then read skb_shinfo(skb)-\u003enr_frags):\n\n  BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000\n  Read of size 8 at addr 000000006163ae78 by task insmod/30\n  freed 208-byte region [000000006163adc0, 000000006163ae90)\n\nQEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF\ndriver does not include the VEPA source pruning path, so a full\nend-to-end reproduction with emulated hardware was not possible.","modified":"2026-07-22T03:32:10.564635914Z","published":"2026-07-19T15:40:14.251Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64113.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb"},{"type":"WEB","url":"https://git.kernel.org/stable/c/55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5d49b568c188dc77199d8d2b959c91da8cc27cf1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6ef30384a50a50e4a484cddf341bc27de31aa3de"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a244395d8c563ed1bb26c3ef708db6aeeaa08084"},{"type":"WEB","url":"https://git.kernel.org/stable/c/add70e2682c0ad3be2a5810bcf1bc13963ba4df9"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dfef79e09ed2f5df975c98547f97f5d7f8982a24"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e8768bcbe5cd30c4ea36a22022c9ffaa66903693"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64113.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64113"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"bad17234ba702a50aeec50ab04724ee58af89607"},{"fixed":"3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb"},{"fixed":"6ef30384a50a50e4a484cddf341bc27de31aa3de"},{"fixed":"55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1"},{"fixed":"add70e2682c0ad3be2a5810bcf1bc13963ba4df9"},{"fixed":"a244395d8c563ed1bb26c3ef708db6aeeaa08084"},{"fixed":"dfef79e09ed2f5df975c98547f97f5d7f8982a24"},{"fixed":"e8768bcbe5cd30c4ea36a22022c9ffaa66903693"},{"fixed":"5d49b568c188dc77199d8d2b959c91da8cc27cf1"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64113.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.19.0"},{"fixed":"5.10.258"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.209"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.175"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.142"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64113.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}