CVE-2026-64113
Received Received - Intake

Use-After-Free in ixgbevf Linux Kernel Driver

Vulnerability report for CVE-2026-64113, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel ixgbevf *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a use-after-free vulnerability in the Linux kernel's ixgbevf driver. It occurs when the driver incorrectly handles skb (socket buffer) pointers during multicast source pruning. The bug allows a freed skb to be accessed in subsequent iterations of a loop, leading to memory corruption in NAPI softirq context.

Detection Guidance

This vulnerability is specific to the ixgbevf Linux kernel driver and requires static analysis or kernel debugging tools to detect. There are no direct network commands to detect it. Use static analysis tools like semgrep or scan_drop_continue_loops.py to scan kernel code for the use-after-free pattern. Kernel Address Sanitizer (KASAN) can also detect this issue during runtime if the vulnerable code path is triggered.

Impact Analysis

This vulnerability could cause system instability, crashes, or potential privilege escalation if exploited. It affects systems using the ixgbevf driver for Intel 82599 virtual function network interfaces. Exploitation requires specific network conditions but could lead to denial of service or unauthorized access in vulnerable environments.

Compliance Impact

This vulnerability is a use-after-free flaw in the Linux kernel's ixgbevf driver, which could lead to memory corruption or crashes in NAPI softirq context. It does not directly affect compliance with standards like GDPR or HIPAA, as those focus on data protection, privacy, and security controls rather than kernel driver vulnerabilities.

Mitigation Strategies

Apply the Linux kernel patch that fixes this issue. If using a vulnerable kernel version, upgrade to a patched version or disable the ixgbevf driver if not required. Monitor vendor advisories for updates to ixgbevf and apply them promptly. No temporary workarounds are suggested beyond disabling the driver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64113. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart