-
CVE-2026-98020
- EPSS 0.17%
- Veröffentlicht 25.09.2026 10:23:40
- Zuletzt bearbeitet 03.10.2026 11:18:25
- Erkennungen
pds_core: fix cmd_regs access racing BAR unmap on reset
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix cmd_regs access racing BAR unmap on reset pdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path clear/iounmap cmd_regs without devcmd_lock, and pdsc_legacy_firmware_update()'s download loop derefs cmd_regs after dropping and retaking the lock without re-checking. An FLR concurrent with a devlink flash can unmap cmd_regs under an in-flight devcmd, causing a NULL deref or a write to unmapped MMIO. Take devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in the download loop. Only the PF maps cmd_regs and runs devcmd, so skip the unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do. A reset that completes entirely within the unlocked window is not a correctness problem for the image: the device clears its update session, so a resumed download is rejected, and it verifies the staged image before writing a flash slot, reporting PDS_RC_BAD_FW rather than activating it. pdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The interrupt and start/stop readers of those are quiesced before the unmap by pdsc_fw_down(), which frees the interrupts and tears down the queues. The debugfs readers are not, since those files outlive a reset; that is pre-existing and out of scope here.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
f6ec6ac9432941ec85a2221c91b1ecfc85680d89
Version <
0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9
Status
affected
Version
e96094c1d11cce4deb5da3c0500d49041ab845b8
Version <
2cc697565fd19b5ba2d100cdd4a20dd6d263abc2
Status
affected
Version
e96094c1d11cce4deb5da3c0500d49041ab845b8
Version <
fa31bd14c5042c6315bb2182c963f03ca6e79ca4
Status
affected
Version
e96094c1d11cce4deb5da3c0500d49041ab845b8
Version <
09f831bfe39de5b8026fefb3d106b5cc93272170
Status
affected
Version
e96094c1d11cce4deb5da3c0500d49041ab845b8
Version <
7980325b2f71e3f65c1323c39792e2455da6fab6
Status
affected
Version
692488941283d72362274620b9abd28109fc459f
Status
affected
Version
6.6.16
Version <
6.6.158
Status
affected
Version
6.7.4
Version <
6.8
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.8
Status
affected
Version
0
Version <
6.8
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc3
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/2cc697565fd19b5ba2d100cdd4a20dd6d263abc2
https://git.kernel.org/stable/c/fa31bd14c5042c6315bb2182c963f03ca6e79ca4
https://git.kernel.org/stable/c/09f831bfe39de5b8026fefb3d106b5cc93272170
https://git.kernel.org/stable/c/7980325b2f71e3f65c1323c39792e2455da6fab6
https://git.kernel.org/stable/c/0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9