« Volver al listado

CVE-2026-97946

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

x86/amd_node: Fix PCI device reference counting in amd_smn_init()

The local "root" pointer is a temporary variable used during the device search. Therefore, refcount related to the search iterators should be cleaned up after the search is complete.

Use the __free() cleanup macro to ensure the refcount is decremented when the temporary pointer goes out of scope.

Additionally, increment the refcount when caching a root pointer. This ensures the in-use refcount is separate from the temporary search refcounting.

Finally, drop the redundant "root = NULL" before the second search loop. The pci_get_class() iterator always decrements the refcount of its "from" argument, so the first loop can only fall through with "root" already NULL.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97946",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0a4b61d9c2e496b5f0a10e29e355a1465c8738bb",
              "lessThan": "84e3a71d11d8593c127b468d75b2653af5074f81",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0a4b61d9c2e496b5f0a10e29e355a1465c8738bb",
              "lessThan": "aa2a4277ad42fd8f918c6dc652473946a253f7b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0a4b61d9c2e496b5f0a10e29e355a1465c8738bb",
              "lessThan": "27600805e62f800bacf990354632eae4e487d34c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c4ad899a33198ab6335732c769835d035e66894a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.17.8",
              "lessThan": "6.18",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "arch/x86/kernel/amd_node.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "arch/x86/kernel/amd_node.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:22.110",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/27600805e62f800bacf990354632eae4e487d34c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/84e3a71d11d8593c127b468d75b2653af5074f81",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa2a4277ad42fd8f918c6dc652473946a253f7b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/amd_node: Fix PCI device reference counting in amd_smn_init()\n\nThe local \"root\" pointer is a temporary variable used during the device\nsearch. Therefore, refcount related to the search iterators should be cleaned\nup after the search is complete.\n\nUse the __free() cleanup macro to ensure the refcount is decremented when the\ntemporary pointer goes out of scope.\n\nAdditionally, increment the refcount when caching a root pointer. This ensures\nthe in-use refcount is separate from the temporary search refcounting.\n\nFinally, drop the redundant \"root = NULL\" before the second search loop. The\npci_get_class() iterator always decrements the refcount of its \"from\"\nargument, so the first loop can only fall through with \"root\" already NULL."
    }
  ],
  "lastModified": "2026-09-25T11:17:22.110",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}