Database/Control plane, storage & DevOps

Linux liquidio driver (Marvell/Cavium, cached VF pci_dev lookup table): The LiquidIO PF caches VF `pci_dev` pointers
Impact
The LiquidIO PF caches VF pci_dev pointers without taking a reference, so the cached pointers can dangle and are then dereferenced when handling a VF function-level-reset request. A VF triggering an FLR — something a tenant does simply by resetting their own device — drives a use-after-free in the host kernel. FLR is the operation an operator relies on to *clean up* between tenants, so the mechanism intended to enforce the handoff boundary is the one that breaks it.
Who can reach it
A tenant holding a LiquidIO VF issuing a function-level reset, or any path that triggers OCTEON_VF_FLR_REQUEST handling on the PF.
What to do
Kernel upgrade plus host reboot on nodes with Marvell LiquidIO adapters. Rolling drain. Note that LiquidIO is end-of-life hardware still present in older inference fleets — if you are running it, weigh replacing the adapters against maintaining kernel patches for a driver that is no longer actively developed.
References
Related entries
- Dell Secure Connect Gateway: exposed Docker socket gives a local user or container host rootCVE-2026-80238 · Dell Secure Connect Gateway 5.0 (orchestrator container / exposed Docker socket)Critical
- MinIO (OIDC authentication): JWT algorithm confusion in the OIDC login path lets an attacker present a token the serverCVE-2026-33322 · MinIO (OIDC authentication)Critical
- rclone (rc API, options/set): options/set is exposed pre-authentication and can rewrite the running instance's authCVE-2026-41176 · rclone (rc API, options/set)Critical
- rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts anCVE-2026-41179 · rclone (rc API, operations/fsinfo)Critical
- Renovate: unvalidated GitLab Link header redirects credential-bearing pagination requestsCVE-2026-88880 · Renovate (GitLab pagination, HTTP Link header host validation)Critical
- Renovate: unvalidated GitHub Link header sends host credentials to an attacker-controlled serverCVE-2026-88881 · Renovate (GitHub pagination, HTTP Link header host validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.