8.4

CVE-2026-89795

PCI: Allow per function PCI slots to fix slot reset on s390

In the Linux kernel, the following vulnerability has been resolved:

PCI: Allow per function PCI slots to fix slot reset on s390

On s390 systems, which use a machine level hypervisor, PCI devices are
always accessed through a form of PCI pass-through which fundamentally
operates on a per PCI function granularity. This is also reflected in the
s390 PCI hotplug driver which creates hotplug slots for individual PCI
functions. Its reset_slot() function, which is a wrapper for
zpci_hot_reset_device(), thus also resets individual functions.

Currently, the pci_create_slot() assigns the same pci_slot object to
multifunction devices. This approach worked fine on s390 systems that only
exposed virtual functions as individual PCI domains to the operating
system.  Since commit 44510d6fa0c0 ("s390/pci: Handling multifunctions")
s390 supports exposing the topology of multifunction PCI devices by
grouping them in a shared PCI domain. This creates a problem when resetting
a function through the hotplug driver's slot_reset() interface.

When attempting to reset a function through the hotplug driver, the shared
slot assignment causes the wrong function to be reset instead of the
intended one. It also leaks memory as we do create a pci_slot object for
the function, but don't correctly free it in pci_slot_release().

Add a flag for struct pci_slot to allow per function PCI slots for
functions managed through a hypervisor, which exposes individual PCI
functions while retaining the topology. Since we can use all 8 bits for
slot 'number' (for ARI devices), change slot 'number' u16 to account for
special values PCI_SLOT_PLACEHOLDER and PCI_SLOT_ALL_DEVICES.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 44510d6fa0c00aa90b80075caa6b313b25927475
Version < 0d1a7d67f45645106578d65181e4e492dd20ed79
Status affected
Version 44510d6fa0c00aa90b80075caa6b313b25927475
Version < 2050d900f9adbd6d6f38d30e182bcd9ad3108467
Status affected
Version 44510d6fa0c00aa90b80075caa6b313b25927475
Version < ecdcceed4d377b02d4ea036b65f83f962c38ede7
Status affected
Version 44510d6fa0c00aa90b80075caa6b313b25927475
Version < dcc5bec09e23bbc4f9de055a11fce9937244f2c8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.8
Status affected
Version 0
Version < 5.8
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.5
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.053
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2 5.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2050d900f9adbd6d6f38d30e182bcd9ad3108467
https://git.kernel.org/stable/c/ecdcceed4d377b02d4ea036b65f83f962c38ede7
https://git.kernel.org/stable/c/dcc5bec09e23bbc4f9de055a11fce9937244f2c8
https://git.kernel.org/stable/c/0d1a7d67f45645106578d65181e4e492dd20ed79