-
CVE-2026-97441
- EPSS 0.17%
- Veröffentlicht 24.09.2026 16:03:54
- Zuletzt bearbeitet 03.10.2026 11:17:55
- Erkennungen
ata: ahci: fail probe if BAR too small for claimed ports
In the Linux kernel, the following vulnerability has been resolved: ata: ahci: fail probe if BAR too small for claimed ports When an AHCI controller is disabled in BIOS, its HOST_CAP register may contain a bogus value, e.g. 0xFFFFFFFF. Since CAP.NP (Number of Ports) is a zeroes based 5-bit register field, a value of 0x1f means 32 ports. If CAP.NP claims more ports than can physically fit within the mapped BAR region, accessing port registers beyond the BAR boundary causes a kernel panic. Add validation in ahci_init_one() to check that the BAR size is sufficient for the number of ports claimed in CAP.NP. The check calculates the required MMIO size as: required_size = 0x100 (global registers) + max_ports * 0x80 If required_size exceeds the actual BAR size, the probe fails with -ENODEV, preventing the panic and providing a clear error message. [cassel: commit log]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
533a08ea11217100cec7a0ed903cb9b9c892d6f1
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
c717b20100ef8cd06b5237af70ea2cb692e058ce
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
ff0ab535f8febbd32afa5832f8d2d9b06a8d5060
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
6d29b91164424256a759ddabc8f2de1ae09bd3f1
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
df262c828b616450eb351349e91c63447551bd01
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
f2e291043c37a896d7f9797e25a356dceb030177
Status
affected
Version
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version <
c4086c6e1af757e1ff26fa2d2926b3ec0195de79
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
2.6.12
Status
affected
Version
0
Version <
2.6.12
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/df262c828b616450eb351349e91c63447551bd01
https://git.kernel.org/stable/c/f2e291043c37a896d7f9797e25a356dceb030177
https://git.kernel.org/stable/c/c4086c6e1af757e1ff26fa2d2926b3ec0195de79
https://git.kernel.org/stable/c/533a08ea11217100cec7a0ed903cb9b9c892d6f1
https://git.kernel.org/stable/c/6d29b91164424256a759ddabc8f2de1ae09bd3f1
https://git.kernel.org/stable/c/c717b20100ef8cd06b5237af70ea2cb692e058ce
https://git.kernel.org/stable/c/ff0ab535f8febbd32afa5832f8d2d9b06a8d5060