« Volver al listado

CVE-2026-68291

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

idpf: fix max_vport related crash on allocation error during init

Set adapter->max_vports only after successful allocation of vports, netdevs and vport_config buffers. This fixes possible crashes on reset or rmmod, following failed allocation on init

Detalles técnicos trazas, registros y código del informe original
[  305.981402] idpf 0000:83:00.0: enabling device (0100 -> 0102)
[  305.994464] idpf 0000:83:00.0: Device HW Reset initiated
[  320.416872] BUG: kernel NULL pointer dereference, address: 0000000000000000
[  320.416918] #PF: supervisor read access in kernel mode
[  320.416942] #PF: error_code(0x0000) - not-present page
[  320.416963] PGD 2099657067 P4D 0
[  320.416983] Oops: Oops: 0000 [#1] SMP NOPTI
...
[  320.417093] RIP: 0010:idpf_remove+0x118/0x200 [idpf]
[  320.417130] Code: 8b bb 98 09 00 00 e8 17 0f 5b e5 48 8b bb e8 08 00 00 e8 0b 0f 5b e5 66 83 bb 28 06 00 00 00 48 8b bb 20 06 00 00 74 49 31 ed <48> 8b 04 ef 48 85 c0 74 2f 48 8b 78 20 e8 66 58 91 e5 48 8b 83 20
[  320.417183] RSP: 0018:ff7322212903fdb8 EFLAGS: 00010246
[  320.417205] RAX: 0000000000000000 RBX: ff4463de40300000 RCX: ff7322212903fd4c
[  320.417228] RDX: 0000000000000001 RSI: ffffffffa7f7d100 RDI: 0000000000000000
[  320.417250] RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000
[  320.417272] R10: 0000000000000001 R11: ff4463de3a638f58 R12: ff4463be89ac7000
[  320.417294] R13: ff4463be89ac7198 R14: ff4463be94fc7198 R15: ffffffffc0f10f20
[  320.417317] FS:  00007f963c0e6740(0000) GS:ff4463fdd65d8000(0000) knlGS:0000000000000000
[  320.417342] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[  320.417362] CR2: 0000000000000000 CR3: 00000020ba674002 CR4: 0000000000773ef0
[  320.417385] PKRU: 55555554
[  320.417398] Call Trace:
[  320.417412]  <TASK>
[  320.417429]  pci_device_remove+0x42/0xb0
[  320.417459]  device_release_driver_internal+0x1a9/0x210
[  320.417492]  driver_detach+0x4b/0x90
[  320.417516]  bus_remove_driver+0x70/0x100
[  320.417539]  pci_unregister_driver+0x2e/0xb0
[  320.417564]  __do_sys_delete_module.constprop.0+0x190/0x2f0
[  320.417592]  ? kmem_cache_free+0x31e/0x550
[  320.417619]  ? lockdep_hardirqs_on_prepare+0xde/0x190
[  320.417644]  ? do_syscall_64+0x38/0x6b0
[  320.417665]  do_syscall_64+0xc8/0x6b0
[  320.417683]  ? clear_bhb_loop+0x30/0x80
[  320.417706]  entry_SYSCALL_64_after_hwframe+0x76/0x7e
[  320.417727] RIP: 0033:0x7f963bb30beb

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68291",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0fe45467a1041ea3657a7fa3a791c84c104fbd34",
              "lessThan": "9fbe22b7aff0a65984d78ee6b93e2f8179abd1f5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0fe45467a1041ea3657a7fa3a791c84c104fbd34",
              "lessThan": "237f1f7653b8729169af11fae79f01b90d00b87e",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/intel/idpf/idpf_virtchnl.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.7"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.7",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/intel/idpf/idpf_virtchnl.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:18.457",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/237f1f7653b8729169af11fae79f01b90d00b87e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9fbe22b7aff0a65984d78ee6b93e2f8179abd1f5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix max_vport related crash on allocation error during init\n\nSet adapter->max_vports only after successful allocation of vports, netdevs\nand  vport_config buffers. This fixes possible crashes on reset or rmmod,\nfollowing failed allocation on init\n\n[  305.981402] idpf 0000:83:00.0: enabling device (0100 -> 0102)\n[  305.994464] idpf 0000:83:00.0: Device HW Reset initiated\n[  320.416872] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[  320.416918] #PF: supervisor read access in kernel mode\n[  320.416942] #PF: error_code(0x0000) - not-present page\n[  320.416963] PGD 2099657067 P4D 0\n[  320.416983] Oops: Oops: 0000 [#1] SMP NOPTI\n...\n[  320.417093] RIP: 0010:idpf_remove+0x118/0x200 [idpf]\n[  320.417130] Code: 8b bb 98 09 00 00 e8 17 0f 5b e5 48 8b bb e8 08 00 00 e8 0b 0f 5b e5 66 83 bb 28 06 00 00 00 48 8b bb 20 06 00 00 74 49 31 ed <48> 8b 04 ef 48 85 c0 74 2f 48 8b 78 20 e8 66 58 91 e5 48 8b 83 20\n[  320.417183] RSP: 0018:ff7322212903fdb8 EFLAGS: 00010246\n[  320.417205] RAX: 0000000000000000 RBX: ff4463de40300000 RCX: ff7322212903fd4c\n[  320.417228] RDX: 0000000000000001 RSI: ffffffffa7f7d100 RDI: 0000000000000000\n[  320.417250] RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000\n[  320.417272] R10: 0000000000000001 R11: ff4463de3a638f58 R12: ff4463be89ac7000\n[  320.417294] R13: ff4463be89ac7198 R14: ff4463be94fc7198 R15: ffffffffc0f10f20\n[  320.417317] FS:  00007f963c0e6740(0000) GS:ff4463fdd65d8000(0000) knlGS:0000000000000000\n[  320.417342] CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[  320.417362] CR2: 0000000000000000 CR3: 00000020ba674002 CR4: 0000000000773ef0\n[  320.417385] PKRU: 55555554\n[  320.417398] Call Trace:\n[  320.417412]  <TASK>\n[  320.417429]  pci_device_remove+0x42/0xb0\n[  320.417459]  device_release_driver_internal+0x1a9/0x210\n[  320.417492]  driver_detach+0x4b/0x90\n[  320.417516]  bus_remove_driver+0x70/0x100\n[  320.417539]  pci_unregister_driver+0x2e/0xb0\n[  320.417564]  __do_sys_delete_module.constprop.0+0x190/0x2f0\n[  320.417592]  ? kmem_cache_free+0x31e/0x550\n[  320.417619]  ? lockdep_hardirqs_on_prepare+0xde/0x190\n[  320.417644]  ? do_syscall_64+0x38/0x6b0\n[  320.417665]  do_syscall_64+0xc8/0x6b0\n[  320.417683]  ? clear_bhb_loop+0x30/0x80\n[  320.417706]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[  320.417727] RIP: 0033:0x7f963bb30beb"
    }
  ],
  "lastModified": "2026-08-17T05:18:31.777",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}