-
CVE-2026-97505
- EPSS 0.16%
- Veröffentlicht 24.09.2026 16:04:54
- Zuletzt bearbeitet 28.09.2026 06:16:36
- Erkennungen
PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store()
In the Linux kernel, the following vulnerability has been resolved: PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store() Currently, the __resource_resize_store() allows writing to the resourceN_resize sysfs attribute to change a BAR's size without checking for capabilities, currently relying only on the file access check. Resizing a BAR modifies PCI device configuration and can disrupt active drivers. After the upcoming conversion to static attributes, it will also trigger resource file updates via sysfs_update_groups(). Add a CAP_SYS_ADMIN check to prevent unprivileged users from performing BAR resize operations.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
91fa127794ac1c48069479b9d45eb4c7378c0e30
Version <
b722a607f858b9cd036075ea0efad553fb98e982
Status
affected
Version
91fa127794ac1c48069479b9d45eb4c7378c0e30
Version <
cbf0628c0b7db86c5ce36451f088101546acbf1d
Status
affected
Version
91fa127794ac1c48069479b9d45eb4c7378c0e30
Version <
25ec7f57deceec633f27bc93b615f951e2ade814
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.1
Status
affected
Version
0
Version <
6.1
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.039 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/b722a607f858b9cd036075ea0efad553fb98e982
https://git.kernel.org/stable/c/cbf0628c0b7db86c5ce36451f088101546acbf1d
https://git.kernel.org/stable/c/25ec7f57deceec633f27bc93b615f951e2ade814