7.1

CVE-2026-89731

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

In the Linux kernel, the following vulnerability has been resolved:

cxl/ras: Fix cxl_rch_get_aer_info() out-of-bounds AER register read

cxl_rch_get_aer_info() copies the RCH Downstream Port AER capability from
the RCRB MMIO block using a readl() loop bounded by sizeof(struct
aer_capability_regs). This struct is a software layout and its embedded
struct pcie_tlp_log is larger than the on-wire AER capability. As a
result the loop reads past the mapped AER register block.

The over-read also populates the software-only tail fields including
header_log.header_len. An out-of-range header_len passed to
pcie_print_tlp_log() can then loop past the header log buffer and cause
a second out-of-bounds read.

The read was correct when introduced, but struct pcie_tlp_log has since
grown (Header Log and TLP Prefix Log sizes, header_len and flit fields),
so sizeof(struct aer_capability_regs) no longer matches the physical AER
capability.

Bound the read to the physical AER registers, header through the 16 byte
Header Log. Zero the destination first so the software-only fields are
deterministic.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Version < 7f5a2a330dde8e8aa2dd80e1f3e05b6ada049607
Status affected
Version 6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Version < 8bd3523df1319edc61cd391e695c84a4618516df
Status affected
Version 6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Version < 8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced
Status affected
Version 6ac07883dbb5f60f7bc56a13b7a84a382aa9c1ab
Version < 29458e62d0829cbc99435f3e44fd560f9bbf1da7
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.7
Status affected
Version 0
Version < 6.7
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/8bd3523df1319edc61cd391e695c84a4618516df
https://git.kernel.org/stable/c/8e3d9dbb25d3ddbe72b4542ec4f7c4e622fe0ced
https://git.kernel.org/stable/c/29458e62d0829cbc99435f3e44fd560f9bbf1da7
https://git.kernel.org/stable/c/7f5a2a330dde8e8aa2dd80e1f3e05b6ada049607