Review reviewHigh

CVE-2026-64222

Linux

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the pointer unchanged. Later, otx2_sq_aura_pool_init() unwinds the partial setup through otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific cn20k_pool_aq_init() implementation has the same bug in its corresponding error path. Set pool->stack to NULL immediately after the local free so the shared cleanup path does not free the same stack again wh...

CVSS
7
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: avoid double free of pool->stack on AQ init failure otx2_pool_aq_init() frees pool->stack when mailbox sync or retry allocation fails, but leaves the pointer unchanged. Later, otx2_sq_aura_pool_init() unwinds the partial setup through otx2_aura_pool_free(), which frees pool->stack again. The CN20K-specific cn20k_pool_aq_init() implementation has the same bug in its corresponding error path. Set pool->stack to NULL immediately after the local free so the shared cleanup path does not free the same stack again wh...

Affected product and versions

Product
Linux
Affected versions
>= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < e6e9bc0bf963662b7042048ab0281014625d4cb4, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < b92e7ea408b6f1144648909c9c49a55d245d7300, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 94192b0579333c3deee2441379aab8ca98fc2e6b, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 4c29603498b05c049dbbbc47e882f2fbf0193cd7, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 0488a0bb344fb1992853b60082acff6be8164d74, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 0d9b9d7dbef976ae7f855b6358f1d703014e96ea, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < c4b8c5d51632538b19ee01cf6d70cbceeefbd3ec, >= caa2da34fd25a37e9fd43343b6966fb9d730a6d5 < 9b244c242bec48b37e82b89787afd6a4c43457e1, >= 5.6
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64222 — Linux | SECUFOCUS NOW