{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64122","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.036Z","datePublished":"2026-07-19T15:40:20.446Z","dateUpdated":"2026-08-05T12:39:28.664Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:39:28.664Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover\n\nmlx5e_tx_reporter_timeout_recover() accesses sq->netdev after\nmlx5e_safe_reopen_channels() has torn down and freed the channel (and\nits embedded SQs). Replace the three sq->netdev references with\npriv->netdev which is safe because priv outlives channel teardown.\n\nThe netdev_err() call already used priv->netdev for this reason; make\nthe trylock/unlock and health_channel_eq_recover calls consistent.\n\nThis fixes the following KASAN splat:\n\n  BUG: KASAN: use-after-free in mlx5e_tx_reporter_timeout_recover+0x1dd/0x360 [mlx5_core]\n  Read of size 8 at addr ffff889860ed0b28 by task kworker/u113:2/5277\n\n  Call Trace:\n   mlx5e_tx_reporter_timeout_recover+0x1dd/0x360 [mlx5_core]\n   devlink_health_reporter_recover+0xa2/0x150\n   devlink_health_report+0x254/0x7c0\n   mlx5e_reporter_tx_timeout+0x297/0x380 [mlx5_core]\n   mlx5e_tx_timeout_work+0x109/0x170 [mlx5_core]\n   process_one_work+0x677/0xf20\n   worker_thread+0x51f/0xd90\n   kthread+0x3a5/0x810\n   ret_from_fork+0x208/0x400\n   ret_from_fork_asm+0x1a/0x30"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The bug is reached from the mlx5e netdev TX-timeout watchdog recovery path on Mellanox ConnectX NICs deployed on internet-facing cloud/datacenter servers; remote peers generate outbound traffic that can stall TX queues and fire `ndo_tx_timeout`, leading to `mlx5e_tx_reporter_timeout_recover()` without any local syscall.\nAC:L - Once a TX timeout occurs, recovery is deterministic: `mlx5e_health_channel_eq_recover()` typically fails when no EQEs are pending, `mlx5e_safe_reopen_channels()` frees the embedded SQ, and the stale `sq->netdev` dereference in `netdev_unlock()` always follows on that fallback path rather than requiring a race the attacker cannot influence.\nPR:N - No capability checks or authentication gates exist on the TX-timeout → devlink health auto-recover call chain; an unauthenticated remote attacker who can send traffic to a host mlx5 interface can induce the watchdog/recovery sequence without root, CAP_NET_ADMIN, or user-namespace privileges.\nUI:N - Exploitation requires no victim user action such as mounting a filesystem or opening a file; it is triggered automatically by the kernel netdev watchdog and workqueue recovery once TX queues stall.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same host kernel security authority; this is not a VM-guest-to-host escape, IOMMU bypass, or other cross-boundary scenario.\nC:H - The KASAN splat confirms an 8-byte use-after-free read of `sq->netdev` from freed channel/SQ memory; UAF on this structure pointer can be leveraged for arbitrary kernel memory disclosure via heap reuse and controlled reads through the corrupted `net_device` reference.\nI:H - The UAF supplies a controlled `struct net_device *` to `netdev_unlock()`, which performs `mutex_unlock()` on attacker-influenced freed memory, enabling heap spraying and memory corruption primitives that can be developed into arbitrary kernel write or code execution.\nA:H - Use-after-free in kernel TX recovery provably causes KASAN faults and can panic or oops the host during `netdev_unlock()` on freed SQ memory, producing complete loss of kernel availability on affected mlx5 systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/reporter_tx.c"],"versions":[{"version":"4329514c61abefe4961541b128c549b017bab5ad","lessThan":"1604a2d68414aa4cc34faac0b7faa9c14455e8d3","status":"affected","versionType":"git"},{"version":"83ac0304a2d77519dae1e54c9713cbe1aedf19c9","lessThan":"152295aa7dc2c5e046606f7dadc84fce41136446","status":"affected","versionType":"git"},{"version":"83ac0304a2d77519dae1e54c9713cbe1aedf19c9","lessThan":"7d260c5d2d89eb2c8c528d54b576b3aae3e20231","status":"affected","versionType":"git"},{"version":"63f9d5fb4d8040077df801ca3270e2f02d55e0d9","status":"affected","versionType":"git"},{"version":"6.18.14","lessThan":"6.18.34","status":"affected","versionType":"semver"},{"version":"6.19.4","lessThan":"6.20","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/mellanox/mlx5/core/en/reporter_tx.c"],"versions":[{"version":"7.0","status":"affected"},{"version":"0","lessThan":"7.0","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18.14","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"7.0","versionEndExcluding":"7.1"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.4"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1604a2d68414aa4cc34faac0b7faa9c14455e8d3"},{"url":"https://git.kernel.org/stable/c/152295aa7dc2c5e046606f7dadc84fce41136446"},{"url":"https://git.kernel.org/stable/c/7d260c5d2d89eb2c8c528d54b576b3aae3e20231"}],"title":"net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover","x_generator":{"engine":"bippy-1.2.0"}}}}