Linux Kernel Vulnerability in OcteonTX2 and CN20K Products
CVE-2026-64222

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-64222?

A vulnerability in the Linux kernel affects the OcteonTX2 and CN20K architectures, specifically within the handling of memory pools. The issue arises during error conditions in octeontx2-pf, where a double free of the pool->stack can occur if the allocation process fails. The otx2_pool_aq_init() function mistakenly does not nullify the pool->stack pointer after a free operation, leading to potential memory corruption when the cleanup function is invoked. This bug originated from an experimental analysis tool developed for detecting memory management problems, with confirmed presence in pre-release versions of the kernel. Resolution requires specific hardware conditions for validation.

Affected Version(s)

Linux caa2da34fd25a37e9fd43343b6966fb9d730a6d5

Linux caa2da34fd25a37e9fd43343b6966fb9d730a6d5

Linux caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 94192b0579333c3deee2441379aab8ca98fc2e6b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.