{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64224","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.770Z","datePublished":"2026-07-24T15:23:09.209Z","dateUpdated":"2026-07-24T15:23:09.209Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-07-24T15:23:09.209Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: fix double free in rvu_rep_rsrc_init()\n\nrvu_rep_rsrc_init() allocates queue memory before calling\notx2_init_hw_resources(). When hardware resource setup fails,\notx2_init_hw_resources() already unwinds the partially initialized\nSQ, CQ, and aura state before returning an error. The representor\nerror path then calls otx2_free_hw_resources() again and can free\nthe same resources a second time.\n\nFix this by splitting the cleanup labels so that a failure from\notx2_init_hw_resources() only releases queue memory. Keep the\notx2_free_hw_resources() call for failures that happen after\nhardware resource initialization completed successfully.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc3.\n\nRuntime validation was not performed because reproducing this path\nrequires OcteonTX2 representor hardware."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/rep.c"],"versions":[{"version":"3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a","lessThan":"8864b664d0443ecb8e56690e5546fcda5fe5e81b","status":"affected","versionType":"git"},{"version":"3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a","lessThan":"eb72a65f2bb2cc059e2ca5d83de01fdf3ea602ad","status":"affected","versionType":"git"},{"version":"3937b7308d4fce2793fa7fa56ed0faf0f8b6dc7a","lessThan":"e8fb3de2a8effcaf62bec2c56b93d8bb480371d1","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/marvell/octeontx2/nic/rep.c"],"versions":[{"version":"6.13","status":"affected"},{"version":"0","lessThan":"6.13","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/8864b664d0443ecb8e56690e5546fcda5fe5e81b"},{"url":"https://git.kernel.org/stable/c/eb72a65f2bb2cc059e2ca5d83de01fdf3ea602ad"},{"url":"https://git.kernel.org/stable/c/e8fb3de2a8effcaf62bec2c56b93d8bb480371d1"}],"title":"octeontx2-pf: fix double free in rvu_rep_rsrc_init()","x_generator":{"engine":"bippy-1.2.0"}}}}