« Volver al listado

CVE-2026-80620

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Revert "PCI/MSI: Unmap MSI-X region on error"

This reverts commit 1a8d4c6ecb4c81261bcdf13556abd4a958eca202.

Commit 1a8d4c6ecb4c ("PCI/MSI: Unmap MSI-X region on error") added an iounmap(dev->msix_base) on the error path of msix_capability_init() to release the MSI-X region when msix_setup_interrupts() fails.

When msix_setup_interrupts() fails, the call chain is:

The __free(free_msi_irqs) cleanup calls pci_free_msi_irqs(), which already handles the unmap:

So dev->msix_base is unmapped and set to NULL before msix_setup_interrupts() returns to msix_capability_init().

Leer descripción completaMostrar menos

The "goto out_unmap" introduced by commit 1a8d4c6ecb4c ("PCI/MSI: Unmap MSI-X region on error") then calls iounmap() a second time on a NULL pointer.

This was reproduced on Intel Emerald Rapids (192 CPUs) while running tools/testing/selftests/kexec/test_kexec_jump.sh:

RDI=0 confirms iounmap() is called with NULL.

Restore the original "goto out_disable" and leave the unmap to the existing __free(free_msi_irqs) cleanup.

Detalles técnicos trazas, registros y código del informe original
  msix_setup_interrupts()
    -> __msix_setup_interrupts()
         struct pci_dev *dev __free(free_msi_irqs) = __dev;
         ...
         return ret;  // __free cleanup fires on error

  void pci_free_msi_irqs(struct pci_dev *dev)
  {
      pci_msi_teardown_msi_irqs(dev);
      if (dev->msix_base) {
          iounmap(dev->msix_base);   // already unmapped here
          dev->msix_base = NULL;     // and set to NULL
      }
  }

  WARNING: CPU#44 at iounmap+0x2a/0xe0
  RIP: 0010:iounmap+0x2a/0xe0
  RDI: 0000000000000000
  Call Trace:
   msix_capability_init+0x317/0x3f0
   __pci_enable_msix_range+0x21d/0x2c0
   pci_alloc_irq_vectors_affinity+0xa9/0x130
   nvme_setup_io_queues+0x2a8/0x420 [nvme]
   nvme_reset_work+0x151/0x340 [nvme]
   ...

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80620",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4a7589b615a3db6792d36b874add86cd22188c95",
              "lessThan": "82e120a7dd566c476ba923d30e3fb78e8118a1dd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5f007c6acaa7d9a543b492c1e48c48a0ea1d7147",
              "lessThan": "6848ca381edff84f87dd1b6973848c271541e813",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76f7abd4ee0188f06465bdd3c053fdc5e8595152",
              "lessThan": "0a2aeb02894b839ecc3ece6dc7e5c3d6c3def16f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aee8db5f048616990dbdefcc25689ade0a2620ec",
              "lessThan": "f79519f636059b007d6abc91652f36dea4f54a20",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a8d4c6ecb4c81261bcdf13556abd4a958eca202",
              "lessThan": "3691a82be2095abaf3326a1cbf7b25858a1d959c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1a8d4c6ecb4c81261bcdf13556abd4a958eca202",
              "lessThan": "f64e03da0d83cb173743888bff4a7e61476a8fc2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "19bf27b450fcd5309bacd614b12bd7de1ac6535b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.1.165",
              "lessThan": "6.1.178",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.128",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.75",
              "lessThan": "6.12.97",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.16",
              "lessThan": "6.18.40",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.6",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "drivers/pci/msi/msi.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/pci/msi/msi.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-28T08:16:46.083",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0a2aeb02894b839ecc3ece6dc7e5c3d6c3def16f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3691a82be2095abaf3326a1cbf7b25858a1d959c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6848ca381edff84f87dd1b6973848c271541e813",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82e120a7dd566c476ba923d30e3fb78e8118a1dd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f64e03da0d83cb173743888bff4a7e61476a8fc2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f79519f636059b007d6abc91652f36dea4f54a20",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"PCI/MSI: Unmap MSI-X region on error\"\n\nThis reverts commit 1a8d4c6ecb4c81261bcdf13556abd4a958eca202.\n\nCommit 1a8d4c6ecb4c (\"PCI/MSI: Unmap MSI-X region on error\") added an\niounmap(dev->msix_base) on the error path of msix_capability_init() to\nrelease the MSI-X region when msix_setup_interrupts() fails.\n\nWhen msix_setup_interrupts() fails, the call chain is:\n\n  msix_setup_interrupts()\n    -> __msix_setup_interrupts()\n         struct pci_dev *dev __free(free_msi_irqs) = __dev;\n         ...\n         return ret;  // __free cleanup fires on error\n\nThe __free(free_msi_irqs) cleanup calls pci_free_msi_irqs(), which\nalready handles the unmap:\n\n  void pci_free_msi_irqs(struct pci_dev *dev)\n  {\n      pci_msi_teardown_msi_irqs(dev);\n      if (dev->msix_base) {\n          iounmap(dev->msix_base);   // already unmapped here\n          dev->msix_base = NULL;     // and set to NULL\n      }\n  }\n\nSo dev->msix_base is unmapped and set to NULL before\nmsix_setup_interrupts() returns to msix_capability_init(). The\n\"goto out_unmap\" introduced by commit 1a8d4c6ecb4c (\"PCI/MSI: Unmap\nMSI-X region on error\") then calls iounmap() a second time on a NULL\npointer.\n\nThis was reproduced on Intel Emerald Rapids (192 CPUs) while\nrunning tools/testing/selftests/kexec/test_kexec_jump.sh:\n\n  WARNING: CPU#44 at iounmap+0x2a/0xe0\n  RIP: 0010:iounmap+0x2a/0xe0\n  RDI: 0000000000000000\n  Call Trace:\n   msix_capability_init+0x317/0x3f0\n   __pci_enable_msix_range+0x21d/0x2c0\n   pci_alloc_irq_vectors_affinity+0xa9/0x130\n   nvme_setup_io_queues+0x2a8/0x420 [nvme]\n   nvme_reset_work+0x151/0x340 [nvme]\n   ...\n\nRDI=0 confirms iounmap() is called with NULL.\n\nRestore the original \"goto out_disable\" and leave the unmap to the\nexisting __free(free_msi_irqs) cleanup."
    }
  ],
  "lastModified": "2026-08-28T08:16:46.083",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}