Descripción
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF rvu_mbox_handler_lmtst_tbl_setup() uses req->base_pcifunc as a direct index into the LMT map table to read another function-s LMTLINE physical base address and copy it into the caller-s own LMT map table entry. The mailbox dispatcher authenticates req->hdr.pcifunc from the IRQ source, but req->base_pcifunc is a separate payload field and is not sanitized. Reject the request with -EPERM when a VF caller-s base_pcifunc is not a valid function under its own PF. is_pf_func_valid() bounds the FUNC field to the PF-s configured VF count, keeping the computed index inside the caller-s own slot block.
CVSS 8.8EPSS 0.164%Riesgo 0.89
Ver fuente- Publicación
- 2026-08-15 06:21:13
- Versiones afectadas
- unknown
- Tipo
- Kernel
- Última modificación
- 2026-08-23 13:16:38
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H