SB2026032097 - Exposed IOCTL with Insufficient Access Control in Linux kernel cavium liquidio driver



SB2026032097 - Exposed IOCTL with Insufficient Access Control in Linux kernel cavium liquidio driver

Published: March 20, 2026

Security Bulletin ID SB2026032097
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Exposed IOCTL with Insufficient Access Control (CVE-ID: CVE-2026-23256)

The vulnerability allows a local user to cause a memory leak.

The vulnerability exists due to an off-by-one error in the VF setup_nic_devices() cleanup function in the net: liquidio component when initializing network devices. A local user can trigger a failure during device setup to cause a memory leak.

The vulnerability specifically affects the cleanup logic in setup_nic_devices() where the loop fails to release memory for the current index on error path. This requires the ability to configure or trigger virtual function (VF) device initialization, typically available to privileged users.


Remediation

Install update from vendor's website.