CVE-2026-64122
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix use-after-free in mlx5etxreportertimeoutrecover
mlx5etxreportertimeoutrecover() accesses sq->netdev after
mlx5esafereopen_channels() has torn down and freed the channel (and
its embedded SQs). Replace the three sq->netdev references with
priv->netdev which is safe because priv outlives channel teardown.
The netdev_err() call already used priv->netdev for this reason; make
the trylock/unlock and healthchanneleq_recover calls consistent.
This fixes the following KASAN splat:
BUG: KASAN: use-after-free in mlx5etxreportertimeoutrecover+0x1dd/0x360 [mlx5_core]
Read of size 8 at addr ffff889860ed0b28 by task kworker/u113:2/5277
Call Trace:
mlx5etxreportertimeoutrecover+0x1dd/0x360 [mlx5_core]
devlinkhealthreporter_recover+0xa2/0x150
devlinkhealthreport+0x254/0x7c0
mlx5ereportertxtimeout+0x297/0x380 [mlx5core]
mlx5etxtimeoutwork+0x109/0x170 [mlx5core]
processonework+0x677/0xf20
worker_thread+0x51f/0xd90
kthread+0x3a5/0x810
retfromfork+0x208/0x400
retfromfork_asm+0x1a/0x30
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/152295aa7dc2c5e046606f7dadc84fce41136446, https://git.kernel.org/stable/c/1604a2d68414aa4cc34faac0b7faa9c14455e8d3, https://git.kernel.org/stable/c/7d260c5d2d89eb2c8c528d54b576b3aae3e20231, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64122.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64122, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git