Database/Control plane, storage & DevOps
Linux octeontx2-af (VF clobbering shared CGX PKIND state): PF and VF NIX logical functions that share a CGX MAC reuse
Impact
PF and VF NIX logical functions that share a CGX MAC reuse the same hardware packet-parse (PKIND) programming, and a VF allocating a NIX LF could reset the MAC's RX PKIND and default TX parse configuration set up by the PF. Parse configuration determines how the adapter interprets every frame on that MAC — so a tenant VF can change packet interpretation for everyone sharing the physical port, including the operator. The fix adds an explicit permission check that was simply absent.
Who can reach it
A tenant VF on an OCTEON adapter allocating a NIX logical function on a CGX MAC shared with the PF or with other tenants.
What to do
Kernel upgrade plus host reboot on OCTEON nodes. Rolling drain. Structurally, avoid sharing a single CGX MAC between an operator PF and tenant VFs where the platform allows dedicating MACs instead — a provisioning-layout decision rather than a patch.
References
Related entries
- SkyPilot (API server, service account role update authorization): SkyPilot never checks whether the caller is entitledCVE-2026-75481 · SkyPilot (API server, service account role update authorization)High
- Citrix NetScaler ADC/Gateway: memory overflow in Gateway and AAA vservers causes denial of serviceCVE-2026-8452 · Citrix NetScaler ADC / Gateway (Gateway and AAA virtual servers)High
- Jenkins: config.xml nested objects reachable via Stapler give authenticated users remote code executionCVE-2026-84645 · Jenkins controller (config.xml submission, Stapler request routing)High
- Jenkins Stapler: form data binding instantiates configuration types the target field never expectedCVE-2026-84647 · Jenkins Stapler (form data binding type restriction)High
- Jenkins: unescaped system log metadata lets an agent-controlled process store XSS in the controller UICVE-2026-84648 · Jenkins controller (system log viewer, log record metadata escaping)High
- Jenkins Stapler: CSRF crumb embedded in generated JavaScript leaks to same-site attackersCVE-2026-84649 · Jenkins Stapler (dynamically generated JavaScript endpoint, CSRF crumb)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.