GPU VulnDB

Database/Control plane, storage & DevOps

Linux octeontx2-af (Marvell OCTEON CN10K, LMTLINE mailbox handler): TENANT ISOLATION: the OCTEON CN10K admin-function

CVE-2026-72045Control plane, storage & DevOpscurated

Impact

TENANT ISOLATION: the OCTEON CN10K admin-function mailbox handler uses a caller-supplied base_pcifunc as a direct index into the LMT map table, reading *another* PCI function's LMTLINE physical base address and copying it into the caller's own map-table entry. The mailbox dispatcher authenticates the requesting function, then ignores that authentication for the field that selects whose memory window you get. A VF assigned to one tenant can therefore point itself at another function's doorbell region on a shared OCTEON DPU. This is a textbook SR-IOV isolation break: the hardware isolation exists, the software hands out the key.

Who can reach it

A tenant holding an OCTEON VF — an SR-IOV virtual function passed into a VM or container — sending a crafted mailbox request to the admin function.

What to do

Kernel upgrade plus host reboot on every node with Marvell OCTEON CN10K networking. Rolling drain across the fleet; nothing to flash. Until patched, do not assign OCTEON VFs to untrusted tenants — the isolation you are relying on is not being enforced.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.