GPU VulnDB

Database/Control plane, storage & DevOps

Linux octeontx2-af (VF clobbering shared CGX PKIND state): TENANT ISOLATION: PF and VF NIX logical functions that share

CVE-2026-74527Control plane, storage & DevOpscurated

Impact

TENANT ISOLATION: PF and VF NIX logical functions that share a CGX MAC reuse the same hardware packet-parse (PKIND) programming, and a VF allocating a NIX LF could reset the MAC's RX PKIND and default TX parse configuration set up by the PF. Parse configuration determines how the adapter interprets every frame on that MAC — so a tenant VF can change packet interpretation for everyone sharing the physical port, including the operator. The fix adds an explicit permission check that was simply absent.

Who can reach it

A tenant VF on an OCTEON adapter allocating a NIX logical function on a CGX MAC shared with the PF or with other tenants.

What to do

Kernel upgrade plus host reboot on OCTEON nodes. Rolling drain. Structurally, avoid sharing a single CGX MAC between an operator PF and tenant VFs where the platform allows dedicating MACs instead — a provisioning-layout decision rather than a patch.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.