Answer in brief
CVE-2026-64113 records a Critical severity (CVSS 9.8) vulnerability in ixgbevf: fix use-after-free in VEPA multicast source pruning. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bad17234ba702a50aeec50ab04724ee58af89607 <3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb || >=bad17234ba702a50aeec50ab04724ee58af89607 <6ef30384a50a50e4a484cddf341bc27de31aa3de || >=bad17234ba702a50aeec50ab04724ee58af89607 <55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1 || >=bad17234ba702a50aeec50ab04724ee58af89607 <add70e2682c0ad3be2a5810bcf1bc13963ba4df9 || >=bad17234ba702a50aeec50ab04724ee58af89607 <a244395d8c563ed1bb26c3ef708db6aeeaa08084 || >=bad17234ba702a50aeec50ab04724ee58af89607 <dfef79e09ed2f5df975c98547f97f5d7f8982a24 || >=bad17234ba702a50aeec50ab04724ee58af89607 <e8768bcbe5cd30c4ea36a22022c9ffaa66903693 || >=bad17234ba702a50aeec50ab04724ee58af89607 <5d49b568c188dc77199d8d2b959c91da8cc27cf1 | 3d931ac62411a7e43b85dba5fe45e1a4a91bd5cb, 6ef30384a50a50e4a484cddf341bc27de31aa3de, 55b3e91d62b2f7a24109b2d7c9f4c66d2e3b1ec1, add70e2682c0ad3be2a5810bcf1bc13963ba4df9, a244395d8c563ed1bb26c3ef708db6aeeaa08084, dfef79e09ed2f5df975c98547f97f5d7f8982a24, e8768bcbe5cd30c4ea36a22022c9ffaa66903693, 5d49b568c188dc77199d8d2b959c91da8cc27cf1 |
| Linux/Linuxgeneric | 3.19 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 12, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.
Quoted source text, attributed separately from HOL analysis.