« Volver al listado

CVE-2026-68317

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

pds_core: fix auxiliary device add/del races

Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler. They serialize on config_lock, but neither guards the slot under it correctly.

add() registers and stores a new auxiliary device without first checking the slot, so a second add of an already-populated slot leaks the first device. del() makes that check outside config_lock, so two concurrent dels can both pass it; the first clears the slot, and the second dereferences a NULL pointer.

Leer descripción completaMostrar menos

Check and update the slot under config_lock in both paths.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68317",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0861fccd43b8bafb533d97308862d20b7db3a2ad",
              "lessThan": "646b58b543f3bb1641e9123b75ff7799fe7b42f1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f41e27b746241e57d968d1d61c008322338ca258",
              "lessThan": "ef194751fed50cf3452017b63f00142a0ab40c70",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
              "lessThan": "cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
              "lessThan": "bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b699bdc720c0255d1bb76cecba7382c1f2107af5",
              "lessThan": "bfa33cd513c7ceb93c5a4c30e5662acd73c0a916",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fec5f7af1d5f64a38f9224cd27b274d1af55a7ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.90",
              "lessThan": "6.6.148",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.28",
              "lessThan": "6.12.101",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.14.6",
              "lessThan": "6.15",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/amd/pds_core/auxbus.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/ethernet/amd/pds_core/auxbus.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-10T13:20:21.690",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/646b58b543f3bb1641e9123b75ff7799fe7b42f1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfa33cd513c7ceb93c5a4c30e5662acd73c0a916",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef194751fed50cf3452017b63f00142a0ab40c70",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix auxiliary device add/del races\n\nTwo paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's\npdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler.\nThey serialize on config_lock, but neither guards the slot under it\ncorrectly.\n\nadd() registers and stores a new auxiliary device without first checking\nthe slot, so a second add of an already-populated slot leaks the first\ndevice. del() makes that check outside config_lock, so two concurrent\ndels can both pass it; the first clears the slot, and the second\ndereferences a NULL pointer.\n\nCheck and update the slot under config_lock in both paths."
    }
  ],
  "lastModified": "2026-08-17T05:18:34.620",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}