Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64225— octeontx2-af: CGX: add bounds check to cgx_speed_mbps index

AI Predicted 5.5 Difficulty: Moderate EPSS 0.18% · P7

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux61071a871ea6eb2125ece91c1a0dbb124a318c8a< 94071141f00bc414e8f8f7f5db3b5143d535299faffected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< 985b5e38ac4f4d5ff03c8bfd8484353b440a1579affected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< 93d3dc81098cd60fb74d434ba7985ddfd9de5acbaffected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< e043017ac429caee73bd30c5a725659f1a3a4568affected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< 8201bf45cc7c1c1a09290c4db8ab1e19801f8fecaffected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< 47a4cf2229be379cf88f92e32e1240337cd6273faffected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< 2c3d26b4a62454945ba9ef3af3174d3e40e7afefaffected
61071a871ea6eb2125ece91c1a0dbb124a318c8a< c0bf0a4f3f1f5f57aa83e1400ba4f56f0abfd542affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64225

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
octeontx2-af: CGX: add bounds check to cgx_speed_mbps index
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index cgx_speed_mbps has 13 elements but RESP_LINKSTAT_SPEED can yield values 0-15. If it returns a value >= 13, this causes an out-of-bounds array access. Add a bounds check and default to speed 0 if the index is out of range.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 4.20版本存在安全漏洞,该漏洞源于cgx_speed_mbps索引边界检查不足,RESP_LINKSTAT_SPEED可返回0-15值,当索引值>=13时导致越界数组访问。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 61071a871ea6eb2125ece91c1a0dbb124a318c8a ~ 94071141f00bc414e8f8f7f5db3b5143d535299f -
LinuxLinux 4.20 -

II. Public POCs for CVE-2026-64225

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64225

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64225 (8)

Same Patch Batch · Linux · 2026-07-24 · 48 CVEs total

CVE-2026-642329.8 CRITICALblock: recompute nr_integrity_segments in blk_insert_cloned_request
CVE-2026-642169.8 CRITICALnetfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
CVE-2026-642558.8 HIGHwifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVE-2026-642478.4 HIGHKVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVE-2026-642358.1 HIGHx86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
CVE-2026-642238.1 HIGHwifi: mac80211: consume only present negotiated TTLM maps
CVE-2026-642267.8 HIGHsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
CVE-2026-642217.8 HIGHspi: ti-qspi: fix use-after-free after DMA setup failure
CVE-2026-642187.8 HIGHbatman-adv: bla: fix report_work leak on backbone_gw purge
CVE-2026-642517.8 HIGHpwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
CVE-2026-642177.8 HIGHnetfs: Fix overrun check in netfs_extract_user_iter()
CVE-2026-642087.5 HIGHcrypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
CVE-2026-642107.5 HIGHnet/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVE-2026-642437.1 HIGHASoC: codecs: simple-mux: Fix enum control bounds check
CVE-2026-642227.0 HIGHocteontx2-pf: avoid double free of pool->stack on AQ init failure
CVE-2026-642197.0 HIGHdrm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_as
CVE-2026-64250LoongArch: Report dying CPU to RCU in stop_this_cpu()
CVE-2026-64252MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVE-2026-64249fpga: region: fix use-after-free in child_regions_with_firmware()
CVE-2026-64220device property: set fwnode->secondary to NULL in fwnode_init()

Showing top 20 of 48 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64225

No comments yet


Leave a comment