CVE-2026-80651
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL
dsm_create() initially checks pdev->bus when computing segment_id:
But the next two lines unconditionally dereference pdev->bus via pcie_find_root_port() and especially pci_dev_id(pdev), which expands to PCI_DEVID(dev->bus->number, dev->devfn). If pdev->bus is in fact NULL, segment_id is initialised to 0 but the very next statement crashes the kernel.
smatch flags this:
Make the NULL handling consistent: if pdev->bus is NULL the device has no PCI context to work with and SEV TIO setup cannot proceed, so return -ENODEV before any of the bus-dependent lookups.
Leer descripción completaMostrar menos
The remaining initialisation now runs only on the path where pdev->bus is known to be valid.
No change for callers where pdev->bus is non-NULL, which is the only case where dsm_create() did meaningful work before this change.
Detalles técnicos trazas, registros y código del informe original
u8 segment_id = pdev->bus ? pci_domain_nr(pdev->bus) : 0;
drivers/crypto/ccp/sev-dev-tsm.c:253 dsm_create() error: we
previously assumed 'pdev->bus' could be null (see line 251)CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80651",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4be423572da1f4c11f45168e3fafda870ddac9f8",
"lessThan": "6bafd740095fb3d0e9a00540bc8f3484c38e6f85",
"versionType": "git"
},
{
"status": "affected",
"version": "4be423572da1f4c11f45168e3fafda870ddac9f8",
"lessThan": "930d9d36ea618a775985446a125aedeb401db522",
"versionType": "git"
}
],
"programFiles": [
"drivers/crypto/ccp/sev-dev-tsm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/crypto/ccp/sev-dev-tsm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-28T08:16:50.110",
"references": [
{
"url": "https://git.kernel.org/stable/c/6bafd740095fb3d0e9a00540bc8f3484c38e6f85",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/930d9d36ea618a775985446a125aedeb401db522",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp/sev-dev-tsm - bail out early when pdev->bus is NULL\n\ndsm_create() initially checks pdev->bus when computing segment_id:\n\n\tu8 segment_id = pdev->bus ? pci_domain_nr(pdev->bus) : 0;\n\nBut the next two lines unconditionally dereference pdev->bus via\npcie_find_root_port() and especially pci_dev_id(pdev), which expands\nto PCI_DEVID(dev->bus->number, dev->devfn). If pdev->bus is in fact\nNULL, segment_id is initialised to 0 but the very next statement\ncrashes the kernel.\n\nsmatch flags this:\n\n drivers/crypto/ccp/sev-dev-tsm.c:253 dsm_create() error: we\n previously assumed 'pdev->bus' could be null (see line 251)\n\nMake the NULL handling consistent: if pdev->bus is NULL the device\nhas no PCI context to work with and SEV TIO setup cannot proceed,\nso return -ENODEV before any of the bus-dependent lookups. The\nremaining initialisation now runs only on the path where pdev->bus\nis known to be valid.\n\nNo change for callers where pdev->bus is non-NULL, which is the\nonly case where dsm_create() did meaningful work before this change."
}
],
"lastModified": "2026-08-28T08:16:50.110",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}