{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-63923","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.021Z","datePublished":"2026-07-19T14:55:24.985Z","dateUpdated":"2026-08-05T12:37:18.035Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:37:18.035Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify\n\nrvu_mbox_handler_rep_event_notify() in drivers/net/ethernet/marvell/\nocteontx2/af/rvu_rep.c queues a sender-controlled REP_EVENT_NOTIFY\nrequest body verbatim, and rvu_rep_up_notify() then forwards\nevent->pcifunc (the nested body field, distinct from the\nAF-normalised header pcifunc) into rvu_get_pfvf(), rvu_get_pf() and\nthe AF->PF mailbox device index without any bounds check.\n\nA VF attached to a PF that has been put into switchdev\nrepresentor mode reaches this path: the VF mailbox handler\notx2_pfvf_mbox_handler() forwards every message id including\nMBOX_MSG_REP_EVENT_NOTIFY to AF without an allowlist, and the AF\ndispatcher rewrites only msg->pcifunc, leaving struct\nrep_event::pcifunc attacker-controlled.  The sibling\nrvu_mbox_handler_esw_cfg() refuses requests whose header pcifunc\nis not rvu->rep_pcifunc; this handler has no equivalent gate.\n\nAn out-of-range body pcifunc selects an &rvu->pf[]/&rvu->hwvf[]\nelement past the allocated array and, for RVU_EVENT_MAC_ADDR_CHANGE,\nturns into a six-byte attacker-chosen OOB ether_addr_copy() target\ninside the queued worker; KASAN reports a slab-out-of-bounds write\nin rvu_rep_wq_handler.\n\nReject malformed requests at the handler entry by gating on\nis_pf_func_valid(), which is already the canonical PF/VF range check\nin this driver; expose it via rvu.h so callers in rvu_rep.c can use\nit instead of open-coding the same range arithmetic."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is reached through the OcteonTX2 VF→PF→AF PCI mailbox control path, not through packet reception or any network protocol. Exploitation requires local access to an assigned SR-IOV VF device on a Marvell OCTEONTX2/CN9K/CN10K NIC.\nAC:L - Once a VF is assigned in switchdev representor mode, the attacker fully controls the malicious `rep_event` body fields (including `pcifunc`, event flags, and MAC data) and can trigger the path deterministically via repeated mailbox messages without races or uncontrollable timing.\nPR:L - Exploitation requires control of an assigned VF (typical cloud/tenant VM or container with SR-IOV passthrough), not host root; the PF mailbox forwarder passes every VF message ID including `MBOX_MSG_REP_EVENT_NOTIFY` to AF without an allowlist or trusted-VF gate on this path.\nUI:N - No victim user action (mounting, clicking, opening files) is required; the attacker triggers the vulnerable handler directly by sending a crafted mailbox message from their VF.\nS:C - In the highest-impact deployment (SR-IOV VF assigned to an untrusted VM/container tenant), corruption occurs in the host AF driver, crossing the guest/host security boundary analogous to device-mediated VM escape rather than a same-authority local privilege change.\nC:H - An out-of-range body `pcifunc` makes `rvu_get_pfvf()` return a pointer past the allocated `rvu->pf[]`/`rvu->hwvf[]` arrays, and the slab-out-of-bounds write corrupts adjacent kernel heap memory in a way that can be leveraged for arbitrary kernel memory disclosure.\nI:H - For `RVU_EVENT_MAC_ADDR_CHANGE`, the worker performs a six-byte attacker-chosen `ether_addr_copy()` to an out-of-bounds `rvu_pfvf` target, constituting an exploitable out-of-bounds kernel heap write suitable for control-flow or privilege-escalation primitives.\nA:H - The out-of-bounds heap write in `rvu_rep_wq_handler` can trigger a kernel oops/panic (as confirmed by KASAN slab-out-of-bounds reports) and can be repeated on demand to deny service to the host."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu.c","drivers/net/ethernet/marvell/octeontx2/af/rvu.h","drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c"],"versions":[{"version":"b8fea84a0468404fe3b3327ad54d583950be9dec","lessThan":"4467fa514482bbce82f73788943c815f3d126ab3","status":"affected","versionType":"git"},{"version":"b8fea84a0468404fe3b3327ad54d583950be9dec","lessThan":"68be0260e2a02ff9b18a8678d5f8d1715fa20138","status":"affected","versionType":"git"},{"version":"b8fea84a0468404fe3b3327ad54d583950be9dec","lessThan":"2156a29aecfffa2eb7c558255690084efbe9f3b0","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/af/rvu.c","drivers/net/ethernet/marvell/octeontx2/af/rvu.h","drivers/net/ethernet/marvell/octeontx2/af/rvu_rep.c"],"versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","status":"unaffected","versionType":"semver"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.12","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.42"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.0.12"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4467fa514482bbce82f73788943c815f3d126ab3"},{"url":"https://git.kernel.org/stable/c/68be0260e2a02ff9b18a8678d5f8d1715fa20138"},{"url":"https://git.kernel.org/stable/c/2156a29aecfffa2eb7c558255690084efbe9f3b0"}],"title":"octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify","x_generator":{"engine":"bippy-1.2.0"}}}}