GHSA-2829-fqm4-jgr9HighCVSS 7.8

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential...

Published
October 15, 2025
Last Modified
July 30, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()

This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node" and then dereferences it on the next line. Two lines later, we take a mutex so I don't think this is an RCU safe region. Re-order it to do the dereferences before queuing up the free.

🔗 References (8)