{"id":"CVE-2026-64222","summary":"octeontx2-pf: avoid double free of pool-\u003estack on AQ init failure","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: avoid double free of pool-\u003estack on AQ init failure\n\notx2_pool_aq_init() frees pool-\u003estack when mailbox sync or retry\nallocation fails, but leaves the pointer unchanged. Later,\notx2_sq_aura_pool_init() unwinds the partial setup through\notx2_aura_pool_free(), which frees pool-\u003estack again. The CN20K-specific\ncn20k_pool_aq_init() implementation has the same bug in\nits corresponding error path.\n\nSet pool-\u003estack to NULL immediately after the local free so the shared\ncleanup path does not free the same stack again while cleaning up\npartially initialized pool state.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still present in\nv7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2/CN20K hardware.","modified":"2026-08-01T03:34:22.401593033Z","published":"2026-07-24T15:23:08.072Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64222.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0488a0bb344fb1992853b60082acff6be8164d74"},{"type":"WEB","url":"https://git.kernel.org/stable/c/0d9b9d7dbef976ae7f855b6358f1d703014e96ea"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4c29603498b05c049dbbbc47e882f2fbf0193cd7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/94192b0579333c3deee2441379aab8ca98fc2e6b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9b244c242bec48b37e82b89787afd6a4c43457e1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b92e7ea408b6f1144648909c9c49a55d245d7300"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6e9bc0bf963662b7042048ab0281014625d4cb4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64222.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64222"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"caa2da34fd25a37e9fd43343b6966fb9d730a6d5"},{"fixed":"e6e9bc0bf963662b7042048ab0281014625d4cb4"},{"fixed":"b92e7ea408b6f1144648909c9c49a55d245d7300"},{"fixed":"94192b0579333c3deee2441379aab8ca98fc2e6b"},{"fixed":"4c29603498b05c049dbbbc47e882f2fbf0193cd7"},{"fixed":"0488a0bb344fb1992853b60082acff6be8164d74"},{"fixed":"0d9b9d7dbef976ae7f855b6358f1d703014e96ea"},{"fixed":"c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec"},{"fixed":"9b244c242bec48b37e82b89787afd6a4c43457e1"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64222.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.6.0"},{"fixed":"5.10.259"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.210"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.176"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.143"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.93"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.35"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64222.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}