PT-2026-86726 · Azure Linux · Kernel
Published
2026-08-28
·
Updated
2026-08-28
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: npc: Fix size of entry2cntr map
KASAN prints below splat. This is caused by allocating counter for
reserved mcam entry for cpt 2nd pass entry. But mcam->entry2cntr map
is not allocated for reserved entries.
BUG: KASAN: slab-out-of-bounds in npc map mcam entry and cntr+0xb0/0x1a0
Write of size 2 at addr ffff0001033e7ffe by task kworker/0:1/14
CPU: 0 PID: 14 Comm: kworker/0:1 Not tainted 6.1.67 #1
Hardware name: Marvell CN106XX board (DT)
Workqueue: events work for cpu fn
Call trace:
dump backtrace.part.0+0xe4/0xf0
show stack+0x18/0x30
dump stack lvl+0x88/0xb4
print report+0x154/0x458
kasan report+0xb8/0x194
asan store2+0x7c/0xa0
npc map mcam entry and cntr+0xb0/0x1a0
rvu mbox handler npc mcam write entry+0x268/0x280
npc install flow+0x840/0xfe0
rvu npc install cpt pass2 entry+0x138/0x190
rvu nix init+0x148c/0x2880
rvu probe+0x1800/0x30b0
local pci probe+0x78/0xe0
work for cpu fn+0x30/0x50
process one work+0x4cc/0x97c
worker thread+0x360/0x630
kthread+0x1a0/0x1b0
ret from fork+0x10/0x20
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel