CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state
In the Linux kernel, the following vulnerability has been resolved:
octeontx2-af: Block VFs from clobbering special CGX PKIND state
PF and VF NIX LFs that share a CGX LMAC reuse the same hardware PKIND programming. When HiGig2 or EDSA parsing is enabled, a VF NIX LF alloc must not reset the LMAC RX PKIND or default TX parse config over the PF setup.
Add cgxgetpkind() and rvucgxispkindconfigpermitted() so VFs skip cgxsetpkind(), rvunpcsetpkind(), and NIXAFLFXTXPARSECFG updates when the LMAC is using NPCRXHIGIGPKIND or NPCRXEDSAPKIND.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-74527?
CVE-2026-74527 has a risk score of 34, indicating a moderate level of severity.
How do I fix CVE-2026-74527?
To fix CVE-2026-74527, ensure that your Linux kernel is updated to the latest version where this vulnerability has been addressed.
What systems are affected by CVE-2026-74527?
CVE-2026-74527 affects systems running specific versions of the Linux kernel that utilize octeontx2-af hardware.
What type of vulnerability is CVE-2026-74527?
CVE-2026-74527 is a hardware programming vulnerability impacting the interaction between PF and VF NIX LFs in the Linux kernel.
When was CVE-2026-74527 published?
CVE-2026-74527 was published on August 15, 2026.