Description
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function-s LMTLINE physical base address and copy it into the caller-s own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not sanitized. Reject the request with -EPERM when a VF caller-s base_pcifunc is not a valid function under its own PF. is_pf_func_valid() bounds the FUNC field to the PF-s configured VF count, keeping the computed index inside the caller-s own slot block.
CVSS 8.8EPSS 0.164%Risk 0.89
View source- Published
- 2026-08-15 06:21:13
- Affected versions
- unknown
- Type
- Kernel
- Last modified
- 2026-08-23 13:16:38
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H