CVE-2026-63923
OOB write via attacker-controlled pcifunc in Marvell OcteonTX2 RVU kernel driver
Is CVE-2026-63923 being exploited?
Not confirmed. CVE-2026-63923 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.17% probability of exploitation in the next 30 days.
How severe is CVE-2026-63923?
CVE-2026-63923 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-63923?
Yes. A fix has been recorded for CVE-2026-63923. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-63923 affect?
CVE-2026-63923 affects Linux kernel drivers/net/ethernet/marvell/octeontx2, Marvell OcteonTX2 RVU/AF driver, Hosts using SR-IOV VFs in representor mode. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-63923?
Apply vendor/kernel patch immediately; if delayed, disable SR-IOV representor mode or block untrusted VFs
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A VF can craft a mailbox to trigger a slab out-of-bounds kernel write, causing kernel memory corruption, DoS, or local privilege escalation.
Immediate action required
- affected>= b8fea84a0468404fe3b3327ad54d583950be9dec and < 4467fa514482bbce82f73788943c815f3d126ab3
- affected>= b8fea84a0468404fe3b3327ad54d583950be9dec and < 68be0260e2a02ff9b18a8678d5f8d1715fa20138
- affected>= b8fea84a0468404fe3b3327ad54d583950be9dec and < 2156a29aecfffa2eb7c558255690084efbe9f3b0
- affected6.13
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.