{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-64122",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T07:54:57.036Z",
        "datePublished": "2026-07-19T15:40:20.446Z",
        "dateUpdated": "2026-08-05T12:39:28.664Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T12:39:28.664Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover\n\nmlx5e_tx_reporter_timeout_recover() accesses sq->netdev after\nmlx5e_safe_reopen_channels() has torn down and freed the channel (and\nits embedded SQs). Replace the three sq->netdev references with\npriv->netdev which is safe because priv outlives channel teardown.\n\nThe netdev_err() call already used priv->netdev for this reason; make\nthe trylock/unlock and health_channel_eq_recover calls consistent.\n\nThis fixes the following KASAN splat:\n\n  BUG: KASAN: use-after-free in mlx5e_tx_reporter_timeout_recover+0x1dd/0x360 [mlx5_core]\n  Read of size 8 at addr ffff889860ed0b28 by task kworker/u113:2/5277\n\n  Call Trace:\n   mlx5e_tx_reporter_timeout_recover+0x1dd/0x360 [mlx5_core]\n   devlink_health_reporter_recover+0xa2/0x150\n   devlink_health_report+0x254/0x7c0\n   mlx5e_reporter_tx_timeout+0x297/0x380 [mlx5_core]\n   mlx5e_tx_timeout_work+0x109/0x170 [mlx5_core]\n   process_one_work+0x677/0xf20\n   worker_thread+0x51f/0xd90\n   kthread+0x3a5/0x810\n   ret_from_fork+0x208/0x400\n   ret_from_fork_asm+0x1a/0x30"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - The bug is reached from the mlx5e netdev TX-timeout watchdog recovery path on Mellanox ConnectX NICs deployed on internet-facing cloud/datacenter servers; remote peers generate outbound traffic that can stall TX queues and fire `ndo_tx_timeout`, leading to `mlx5e_tx_reporter_timeout_recover()` without any local syscall.\nAC:L - Once a TX timeout occurs, recovery is deterministic: `mlx5e_health_channel_eq_recover()` typically fails when no EQEs are pending, `mlx5e_safe_reopen_channels()` frees the embedded SQ, and the stale `sq->netdev` dereference in `netdev_unlock()` always follows on that fallback path rather than requiring a race the attacker cannot influence.\nPR:N - No capability checks or authentication gates exist on the TX-timeout → devlink health auto-recover call chain; an unauthenticated remote attacker who can send traffic to a host mlx5 interface can induce the watchdog/recovery sequence without root, CAP_NET_ADMIN, or user-namespace privileges.\nUI:N - Exploitation requires no victim user action such as mounting a filesystem or opening a file; it is triggered automatically by the kernel netdev watchdog and workqueue recovery once TX queues stall.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same host kernel security authority; this is not a VM-guest-to-host escape, IOMMU bypass, or other cross-boundary scenario.\nC:H - The KASAN splat confirms an 8-byte use-after-free read of `sq->netdev` from freed channel/SQ memory; UAF on this structure pointer can be leveraged for arbitrary kernel memory disclosure via heap reuse and controlled reads through the corrupted `net_device` reference.\nI:H - The UAF supplies a controlled `struct net_device *` to `netdev_unlock()`, which performs `mutex_unlock()` on attacker-influenced freed memory, enabling heap spraying and memory corruption primitives that can be developed into arbitrary kernel write or code execution.\nA:H - Use-after-free in kernel TX recovery provably causes KASAN faults and can panic or oops the host during `netdev_unlock()` on freed SQ memory, producing complete loss of kernel availability on affected mlx5 systems."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/mellanox/mlx5/core/en/reporter_tx.c"
                    ],
                    "versions": [
                        {
                            "version": "4329514c61abefe4961541b128c549b017bab5ad",
                            "lessThan": "1604a2d68414aa4cc34faac0b7faa9c14455e8d3",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "83ac0304a2d77519dae1e54c9713cbe1aedf19c9",
                            "lessThan": "152295aa7dc2c5e046606f7dadc84fce41136446",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "83ac0304a2d77519dae1e54c9713cbe1aedf19c9",
                            "lessThan": "7d260c5d2d89eb2c8c528d54b576b3aae3e20231",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "63f9d5fb4d8040077df801ca3270e2f02d55e0d9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6.18.14",
                            "lessThan": "6.18.34",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.19.4",
                            "lessThan": "6.20",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/mellanox/mlx5/core/en/reporter_tx.c"
                    ],
                    "versions": [
                        {
                            "version": "7.0",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "7.0",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.34",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.0.11",
                            "lessThanOrEqual": "7.0.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.18.14",
                                    "versionEndExcluding": "6.18.34"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "7.0",
                                    "versionEndExcluding": "7.0.11"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "7.0",
                                    "versionEndExcluding": "7.1"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "6.19.4"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/1604a2d68414aa4cc34faac0b7faa9c14455e8d3"
                },
                {
                    "url": "https://git.kernel.org/stable/c/152295aa7dc2c5e046606f7dadc84fce41136446"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7d260c5d2d89eb2c8c528d54b576b3aae3e20231"
                }
            ],
            "title": "net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}