-

CVE-2026-98020

pds_core: fix cmd_regs access racing BAR unmap on reset

In the Linux kernel, the following vulnerability has been resolved:

pds_core: fix cmd_regs access racing BAR unmap on reset

pdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path
clear/iounmap cmd_regs without devcmd_lock, and
pdsc_legacy_firmware_update()'s download loop derefs cmd_regs after
dropping and retaking the lock without re-checking. An FLR concurrent
with a devlink flash can unmap cmd_regs under an in-flight devcmd,
causing a NULL deref or a write to unmapped MMIO.

Take devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in
the download loop. Only the PF maps cmd_regs and runs devcmd, so skip
the unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do.

A reset that completes entirely within the unlocked window is not a
correctness problem for the image: the device clears its update session,
so a resumed download is rejected, and it verifies the staged image
before writing a flash slot, reporting PDS_RC_BAD_FW rather than
activating it.

pdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The
interrupt and start/stop readers of those are quiesced before the unmap
by pdsc_fw_down(), which frees the interrupts and tears down the queues.
The debugfs readers are not, since those files outlive a reset; that is
pre-existing and out of scope here.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f6ec6ac9432941ec85a2221c91b1ecfc85680d89
Version < 0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9
Status affected
Version e96094c1d11cce4deb5da3c0500d49041ab845b8
Version < 2cc697565fd19b5ba2d100cdd4a20dd6d263abc2
Status affected
Version e96094c1d11cce4deb5da3c0500d49041ab845b8
Version < fa31bd14c5042c6315bb2182c963f03ca6e79ca4
Status affected
Version e96094c1d11cce4deb5da3c0500d49041ab845b8
Version < 09f831bfe39de5b8026fefb3d106b5cc93272170
Status affected
Version e96094c1d11cce4deb5da3c0500d49041ab845b8
Version < 7980325b2f71e3f65c1323c39792e2455da6fab6
Status affected
Version 692488941283d72362274620b9abd28109fc459f
Status affected
Version 6.6.16
Version < 6.6.158
Status affected
Version 6.7.4
Version < 6.8
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/2cc697565fd19b5ba2d100cdd4a20dd6d263abc2
https://git.kernel.org/stable/c/fa31bd14c5042c6315bb2182c963f03ca6e79ca4
https://git.kernel.org/stable/c/09f831bfe39de5b8026fefb3d106b5cc93272170
https://git.kernel.org/stable/c/7980325b2f71e3f65c1323c39792e2455da6fab6
https://git.kernel.org/stable/c/0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9