CVE-2026-64113
CVE CVE-2026-64113EUVD EUVD-2026-45798Published 2026-07-19T15:40:14.000ZLast changed 2026-08-05T12:39:22.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux bad17234ba702a50aeec50ab04724ee58af89607 <55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1; bad17234ba702a50aeec50ab04724ee58af89607 <5d49b568c188dc77199d8d2b959c91da8cc27cf1; bad17234ba702a50aeec50ab04724ee58af89607 <e8768bcbe5cd30c4ea36a22022c9ffaa66903693; patch: 6.6.142; 3.19; bad17234ba702a50aeec50ab04724ee58af89607 <dfef79e09ed2f5df975c98547f97f5d7f8982a24; bad17234ba702a50aeec50ab04724ee58af89607 <6ef30384a50a50e4a484cddf341bc27de31aa3de; patch: 7.1; patch: 6.1.175; bad17234ba702a50aeec50ab04724ee58af89607 <3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb; patch: 0; patch: 6.18.34; patch: 5.15.209; patch: 5.10.258; patch: 6.12.92; bad17234ba702a50aeec50ab04724ee58af89607 <a244395d8c563ed1bb26c3ef708db6aeeaa08084; bad17234ba702a50aeec50ab04724ee58af89607 <add70e2682c0ad3be2a5810bcf1bc13963ba4df9; patch: 7.0.11
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.