« Volver al listado

CVE-2026-90082

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Cap MSI-X vectors to the device MSI-X table size

mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix and the CPU count, but never from the device MSI-X table. On a 1792 vCPU M-series VM that yields 1793 while the table has 1024 entries, and mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the end of the region mapped by msix_map_region():

RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table.

msi_insert_desc() does range check the index, but only against the MSI domain hwsize, which matches the table only for devices on an MSI parent domain. With a global PCI/MSI domain hwsize is MSI_XA_DOMAIN_SIZE, so nothing bounds the request.

Leer descripción completaMostrar menos

Cap num_msix_usable with pci_msix_vec_count().

Detalles técnicos trazas, registros y código del informe original
  BUG: unable to handle page fault for address: ff8e347f8b99800c
  RIP: 0010:msix_prepare_msi_desc+0x7a/0x90
  RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000
  Call Trace:
   <TASK>
   __msi_domain_alloc_irqs+0x13a/0x440
   msi_domain_alloc_irq_at+0x149/0x1b0
   mana_gd_setup+0x351/0x890
   mana_gd_probe+0x274/0x390
   </TASK>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90082",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "755391121038c06cb653241aa94dcabd87179f62",
              "lessThan": "4f9827b314ee57cd99f86f8dbadcaf567112e2b2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "755391121038c06cb653241aa94dcabd87179f62",
              "lessThan": "2c7493f980140a5c40eb4f98f97c557193a2c330",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/microsoft/mana/gdma_main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/microsoft/mana/gdma_main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:57.573",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2c7493f980140a5c40eb4f98f97c557193a2c330",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4f9827b314ee57cd99f86f8dbadcaf567112e2b2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Cap MSI-X vectors to the device MSI-X table size\n\nmana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix\nand the CPU count, but never from the device MSI-X table. On a 1792 vCPU\nM-series VM that yields 1793 while the table has 1024 entries, and\nmana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the\nend of the region mapped by msix_map_region():\n\n  BUG: unable to handle page fault for address: ff8e347f8b99800c\n  RIP: 0010:msix_prepare_msi_desc+0x7a/0x90\n  RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000\n  Call Trace:\n   <TASK>\n   __msi_domain_alloc_irqs+0x13a/0x440\n   msi_domain_alloc_irq_at+0x149/0x1b0\n   mana_gd_setup+0x351/0x890\n   mana_gd_probe+0x274/0x390\n   </TASK>\n\nRAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table.\n\nmsi_insert_desc() does range check the index, but only against the MSI\ndomain hwsize, which matches the table only for devices on an MSI parent\ndomain. With a global PCI/MSI domain hwsize is MSI_XA_DOMAIN_SIZE, so\nnothing bounds the request.\n\nCap num_msix_usable with pci_msix_vec_count()."
    }
  ],
  "lastModified": "2026-09-17T17:16:57.573",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}