-
CVE-2026-98142
- EPSS 0.16%
- Veröffentlicht 25.09.2026 10:36:17
- Zuletzt bearbeitet 03.10.2026 11:18:36
- Erkennungen
drm/cirrus-qemu: Validate BAR0 size during probe
In the Linux kernel, the following vulnerability has been resolved: drm/cirrus-qemu: Validate BAR0 size during probe The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate framebuffer sizes. However, during PCI probe, the driver mapped BAR0 without verifying that its size matches `CIRRUS_VRAM_SIZE`. If a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the mapped VRAM will be smaller than expected. Because validation checks assume 4 MB VRAM, framebuffers larger than the mapped memory can be created. When the display plane is updated (e.g. during release), `cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to VRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory causes a supervisor write page fault: BUG: unable to handle page fault for address: ffffc9000389c000 ... RIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110 ... Call Trace: <TASK> iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline] drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442 cirrus_primary_plane_helper_atomic_update+0x98a/0xb00 drivers/gpu/drm/tiny/cirrus-qemu.c:358 drm_atomic_helper_commit_planes+0x626/0xea0 drivers/gpu/drm/drm_atomic_helper.c:3038 drm_atomic_helper_commit_tail+0x60/0x510 drivers/gpu/drm/drm_atomic_helper.c:1989 commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074 drm_atomic_helper_commit+0xa77/0xb10 drivers/gpu/drm/drm_atomic_helper.c:2312 Fix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource is not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version <
2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e
Status
affected
Version
ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version <
0b5084a1f070ad1fc34e11945644ae034bbc774c
Status
affected
Version
ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version <
26bd90c886218f36c9adeab206b0e27b4384e2f6
Status
affected
Version
ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version <
144f51cd0ccc3ad47a6099917b7bb535611fb18f
Status
affected
Version
ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version <
92312d333bf700798f92f30406c721bce87506f3
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.2
Status
affected
Version
0
Version <
5.2
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
7.2.*
Version
7.2.7
Status
unaffected
Version <=
*
Version
7.3-rc2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.041 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c
https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6
https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f
https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3
https://git.kernel.org/stable/c/2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e