Database/Control plane, storage & DevOps

Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): The OCTEON CN10K admin-function mailbox handler
Impact
The OCTEON CN10K admin-function mailbox handler uses a caller-supplied base_pcifunc as a direct index into the LMT map table, reading *another* PCI function's LMTLINE physical base address and copying it into the caller's own map-table entry. The mailbox dispatcher authenticates the requesting function, then ignores that authentication for the field that selects whose memory window you get. A VF assigned to one tenant can therefore point itself at another function's doorbell region on a shared OCTEON DPU. This is a textbook SR-IOV isolation break: the hardware isolation exists, the software hands out the key.
Who can reach it
A tenant holding an OCTEON VF — an SR-IOV virtual function passed into a VM or container — sending a crafted mailbox request to the admin function.
What to do
Kernel upgrade plus host reboot on every node with Marvell OCTEON CN10K networking. Rolling drain across the fleet; nothing to flash. Until patched, do not assign OCTEON VFs to untrusted tenants — the isolation you are relying on is not being enforced.
References
Related entries
- Linux octeontx2-af (VF clobbering shared CGX PKIND state): PF and VF NIX logical functions that share a CGX MAC reuseCVE-2026-74527 · Linux octeontx2-af (VF clobbering shared CGX PKIND state)High
- SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitledCVE-2026-75481 · SkyPilot (API server, service account role update authorization)High
- Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of serviceCVE-2026-8452 · Citrix NetScaler ADC / Gateway (Gateway and AAA virtual servers)High
- Jenkins: config.xml nested objects reachable via Stapler give authenticated users remote code executionCVE-2026-84645 · Jenkins controller (config.xml submission, Stapler request routing)High
- Jenkins Stapler: form data binding instantiates configuration types the target field never expectedCVE-2026-84647 · Jenkins Stapler (form data binding type restriction)High
- Jenkins: unescaped system log metadata lets an agent-controlled process store XSS in the controller UICVE-2026-84648 · Jenkins controller (system log viewer, log record metadata escaping)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.