CVE-2026-80917
In the Linux kernel, the following vulnerability has been resolved:
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
On 32-bit systems the config space is too large to ioremap in one go, so pci_ecam_create() maps each bus segment separately and relies on the ->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in cfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for every config access.
The generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus and ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c do not. As a result, on a 32-bit host using "pci-host-cam-generic" the per-bus mapping is never set up and the first config read dereferences a NULL base, crashing during bus enumeration:
Leer descripción completaMostrar menos
Fix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks. Since pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c, move the CAM ops definition there as pci_generic_cam_ops (mirroring pci_generic_ecam_ops) and export it for pci-host-generic.c to reference.
[mani: removed timestamp from log]
Detalles técnicos trazas, registros y código del informe original
Unable to handle kernel NULL pointer dereference at virtual address 00000800 Oops [#1] CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43 Hardware name: Digilent Nexys-Video-A7 RV32 (DT) epc : pci_generic_config_read+0x40/0xb0 ra : pci_generic_config_read+0x2c/0xb0 [<c038db9c>] pci_generic_config_read+0x40/0xb0 [<c038da04>] pci_bus_read_config_dword+0x50/0xb0 [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec [<c039245c>] pci_scan_single_device+0xa4/0x11c [<c0392570>] pci_scan_slot+0x9c/0x23c [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4 [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8 [<c0393e54>] pci_host_probe+0x20/0xc8 [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984
- https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b
- https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67
- https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108
- https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c
- https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10
- https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354
- https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80917",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "5e52eb0290f66ba0732956dcb1e365b5ca3c5108",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "baf9b0383ff770fdff123d3a832f3a99641d96dd",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "8d08713ec83a18526d1ed1fd5f0d2b901d103a10",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "74456843f18ba7f3045974d7e8b88ab993152b8c",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "0c55707bd5d0d7670704cfd0dda933809b052f67",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "a199293f3038db8d31d47aa60f1e18272cd82354",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "0916948026f623844acd08888f7cbedbf1c48d6b",
"versionType": "git"
},
{
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"lessThan": "008cb88edb41f3c7c8e0ed763ff9f26719830984",
"versionType": "git"
},
{
"status": "affected",
"version": "0b5877a1aeacdbf32b3bea91326592004ec7806f",
"versionType": "git"
},
{
"status": "affected",
"version": "a037ebbe72a4f98495b193112e2b2000e5e09eb5",
"versionType": "git"
},
{
"status": "affected",
"version": "5.12.19",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.13.4",
"lessThan": "5.14",
"versionType": "semver"
}
],
"programFiles": [
"drivers/pci/controller/pci-host-generic.c",
"drivers/pci/ecam.c",
"include/linux/pci-ecam.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.14",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/pci/controller/pci-host-generic.c",
"drivers/pci/ecam.c",
"include/linux/pci-ecam.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-09T17:17:46.680",
"references": [
{
"url": "https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus\nand ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n ra : pci_generic_config_read+0x2c/0xb0\n [<c038db9c>] pci_generic_config_read+0x40/0xb0\n [<c038da04>] pci_bus_read_config_dword+0x50/0xb0\n [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [<c039245c>] pci_scan_single_device+0xa4/0x11c\n [<c0392570>] pci_scan_slot+0x9c/0x23c\n [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4\n [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8\n [<c0393e54>] pci_host_probe+0x20/0xc8\n [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]"
}
],
"lastModified": "2026-09-09T17:17:46.680",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}