Answer in brief
CVE-2026-64118 records a Unknown severity vulnerability in qed: fix double free in qed_cxt_tables_alloc(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64118 records a Unknown severity vulnerability in qed: fix double free in qed_cxt_tables_alloc(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fe56b9e6a8d957d6a20729d626027f800c17a2da <9fe030719bd083b766602692ee96c8c985798e3c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227 || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <3904b993cc17ec5d7c5d3b57dbd0b775dafb9684 || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <bdf678a273cadbccc347f331ae2e93ff4d14834c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <0e47fc1c9181ae029e0e35a865cbf2adcbae626c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <a04c207f0801abdd23a169b5f902a9845059a65a || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <2bccfb8476ca5f3548afbd623dc7a6980d4e77de | 9fe030719bd083b766602692ee96c8c985798e3c, 06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227, 8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb, 3904b993cc17ec5d7c5d3b57dbd0b775dafb9684, bdf678a273cadbccc347f331ae2e93ff4d14834c, 0e47fc1c9181ae029e0e35a865cbf2adcbae626c, a04c207f0801abdd23a169b5f902a9845059a65a, 2bccfb8476ca5f3548afbd623dc7a6980d4e77de |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. qed_cxt_tables_alloc() then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free() again. Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime reproduction was not attempted because exercising the failing allocation path requires device-specific setup.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fe56b9e6a8d957d6a20729d626027f800c17a2da <9fe030719bd083b766602692ee96c8c985798e3c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227 || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <3904b993cc17ec5d7c5d3b57dbd0b775dafb9684 || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <bdf678a273cadbccc347f331ae2e93ff4d14834c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <0e47fc1c9181ae029e0e35a865cbf2adcbae626c || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <a04c207f0801abdd23a169b5f902a9845059a65a || >=fe56b9e6a8d957d6a20729d626027f800c17a2da <2bccfb8476ca5f3548afbd623dc7a6980d4e77de | 9fe030719bd083b766602692ee96c8c985798e3c, 06fa8e69019fd3c41a7b0ea8c5f509c3a33dc227, 8cf5e4d2ca6b101d163c7423a426fb0aec34f7bb, 3904b993cc17ec5d7c5d3b57dbd0b775dafb9684, bdf678a273cadbccc347f331ae2e93ff4d14834c, 0e47fc1c9181ae029e0e35a865cbf2adcbae626c, a04c207f0801abdd23a169b5f902a9845059a65a, 2bccfb8476ca5f3548afbd623dc7a6980d4e77de |
| Linux/Linuxgeneric | 4.4 | Not reported |
Published upstream
Jul 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. qed_cxt_tables_alloc() then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free() again. Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime reproduction was not attempted because exercising the failing allocation path requires device-specific setup.
Quoted source text, attributed separately from HOL analysis.