-

CVE-2026-98142

drm/cirrus-qemu: Validate BAR0 size during probe

In the Linux kernel, the following vulnerability has been resolved:

drm/cirrus-qemu: Validate BAR0 size during probe

The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate
framebuffer sizes. However, during PCI probe, the driver mapped BAR0
without verifying that its size matches `CIRRUS_VRAM_SIZE`.

If a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the
mapped VRAM will be smaller than expected. Because validation checks assume
4 MB VRAM, framebuffers larger than the mapped memory can be created.

When the display plane is updated (e.g. during release),
`cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to
VRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory
causes a supervisor write page fault:

BUG: unable to handle page fault for address: ffffc9000389c000
...
RIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110
...
Call Trace:
 <TASK>
 iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]
 drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442
 cirrus_primary_plane_helper_atomic_update+0x98a/0xb00
 drivers/gpu/drm/tiny/cirrus-qemu.c:358
 drm_atomic_helper_commit_planes+0x626/0xea0
 drivers/gpu/drm/drm_atomic_helper.c:3038
 drm_atomic_helper_commit_tail+0x60/0x510
 drivers/gpu/drm/drm_atomic_helper.c:1989
 commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074
 drm_atomic_helper_commit+0xa77/0xb10
 drivers/gpu/drm/drm_atomic_helper.c:2312

Fix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource
is not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version < 2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e
Status affected
Version ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version < 0b5084a1f070ad1fc34e11945644ae034bbc774c
Status affected
Version ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version < 26bd90c886218f36c9adeab206b0e27b4384e2f6
Status affected
Version ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version < 144f51cd0ccc3ad47a6099917b7bb535611fb18f
Status affected
Version ab3e023b1b4c9887c9f0f761b47f3f0516bd3434
Version < 92312d333bf700798f92f30406c721bce87506f3
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.2
Status affected
Version 0
Version < 5.2
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.041
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c
https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6
https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f
https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3
https://git.kernel.org/stable/c/2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e