CVE-2026-97948
In the Linux kernel, the following vulnerability has been resolved:
powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver
The commit 1010b4c012b0 ("powerpc/eeh: Make EEH driver device hotplug safe") refactored the EEH code such that the pci_rescan_remove_lock is held at the beginning of eeh_handle_normal_event() and the eeh_reset_device() is called with that lock being held. Looks like the commit missed to remove the existing lock/unlock inside eeh_rmv_device() which is no longer necessary. This is causing the eehd to hang on the lock which it actually holds when that code path is taken.
Leer descripción completaMostrar menos
The issue is seen for cases where the errors are detected on the PHB directly AND|OR for devices where the driver error_detected() returns PCI_ERS_RESULT_NEED_RESET, and driver being not EEH sensitive(i.e no error handlers like slot_reset(), resume() etc defined).
Detalles técnicos trazas, registros y código del informe original
[<0>] 0xc00000011c78f870 [<0>] __switch_to+0xfc/0x1a0 [<0>] pci_lock_rescan_remove+0x30/0x44 [<0>] eeh_rmv_device+0x290/0x2e0 [<0>] eeh_pe_dev_traverse+0x80/0x130 [<0>] eeh_reset_device+0xcc/0x23c [<0>] eeh_handle_normal_event+0x830/0xa80 [<0>] eeh_event_handler+0xf8/0x190 [<0>] kthread+0x194/0x1b0 [<0>] start_kernel_thread+0x14/0x18
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 7
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/102e3dc5ab5ba052e294819e83384166b242c1ec
- https://git.kernel.org/stable/c/24524fca27da674668941440e8e05cdfec0b0222
- https://git.kernel.org/stable/c/2920af33d097ca335e492b346af70b72986ad6dc
- https://git.kernel.org/stable/c/3833dfae0680b6b16e2469fbc90aa48376311cd8
- https://git.kernel.org/stable/c/460fab22b65138531082910702f74b048b25237b
- https://git.kernel.org/stable/c/85d8eaefc052cf3e5ae2c7bafeda2db68b8898b4
- https://git.kernel.org/stable/c/a58531181363219fa5de2b53d5d7274dcdfca98b
- https://git.kernel.org/stable/c/c5e68706527968282e49de205cc2b935823cb88a
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-97948",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "502f08831a9afb72dc98a56ae6504da43e93b250",
"lessThan": "3833dfae0680b6b16e2469fbc90aa48376311cd8",
"versionType": "git"
},
{
"status": "affected",
"version": "f56e004b781719d8fdf6c9619b15caf2579bc1f2",
"lessThan": "24524fca27da674668941440e8e05cdfec0b0222",
"versionType": "git"
},
{
"status": "affected",
"version": "59c6d3d81d42bf543c90597b4f38c53d6874c5a1",
"lessThan": "a58531181363219fa5de2b53d5d7274dcdfca98b",
"versionType": "git"
},
{
"status": "affected",
"version": "a426e8a6ae161f51888585b065db0f8f93ab2e16",
"lessThan": "460fab22b65138531082910702f74b048b25237b",
"versionType": "git"
},
{
"status": "affected",
"version": "d2c60a8a387e9fcc28447ef36c03f8e49fd052a6",
"lessThan": "102e3dc5ab5ba052e294819e83384166b242c1ec",
"versionType": "git"
},
{
"status": "affected",
"version": "1010b4c012b0d78dfb9d3132b49aa2ef024a07a7",
"lessThan": "2920af33d097ca335e492b346af70b72986ad6dc",
"versionType": "git"
},
{
"status": "affected",
"version": "1010b4c012b0d78dfb9d3132b49aa2ef024a07a7",
"lessThan": "85d8eaefc052cf3e5ae2c7bafeda2db68b8898b4",
"versionType": "git"
},
{
"status": "affected",
"version": "1010b4c012b0d78dfb9d3132b49aa2ef024a07a7",
"lessThan": "c5e68706527968282e49de205cc2b935823cb88a",
"versionType": "git"
},
{
"status": "affected",
"version": "d42bbd8f30ac38b1ce54715bf08ec3dac18d6b25",
"versionType": "git"
},
{
"status": "affected",
"version": "19d5036e7ad766cf212aebec23b9f1d7924a62bc",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.241",
"lessThan": "5.10.271",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.190",
"lessThan": "5.15.222",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.148",
"lessThan": "6.1.189",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.102",
"lessThan": "6.6.158",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.42",
"lessThan": "6.12.111",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.15.10",
"lessThan": "6.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.16.1",
"lessThan": "6.17",
"versionType": "semver"
}
],
"programFiles": [
"arch/powerpc/kernel/eeh_driver.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"arch/powerpc/kernel/eeh_driver.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:22.317",
"references": [
{
"url": "https://git.kernel.org/stable/c/102e3dc5ab5ba052e294819e83384166b242c1ec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/24524fca27da674668941440e8e05cdfec0b0222",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2920af33d097ca335e492b346af70b72986ad6dc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3833dfae0680b6b16e2469fbc90aa48376311cd8",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/460fab22b65138531082910702f74b048b25237b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/85d8eaefc052cf3e5ae2c7bafeda2db68b8898b4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a58531181363219fa5de2b53d5d7274dcdfca98b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c5e68706527968282e49de205cc2b935823cb88a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/eeh: Fix recursive locking on devices without EEH sensitive driver\n\nThe commit 1010b4c012b0 (\"powerpc/eeh: Make EEH driver device hotplug\nsafe\") refactored the EEH code such that the pci_rescan_remove_lock is\nheld at the beginning of eeh_handle_normal_event() and the\neeh_reset_device() is called with that lock being held. Looks like the\ncommit missed to remove the existing lock/unlock inside eeh_rmv_device()\nwhich is no longer necessary. This is causing the eehd to hang on the\nlock which it actually holds when that code path is taken.\n\n[<0>] 0xc00000011c78f870\n[<0>] __switch_to+0xfc/0x1a0\n[<0>] pci_lock_rescan_remove+0x30/0x44\n[<0>] eeh_rmv_device+0x290/0x2e0\n[<0>] eeh_pe_dev_traverse+0x80/0x130\n[<0>] eeh_reset_device+0xcc/0x23c\n[<0>] eeh_handle_normal_event+0x830/0xa80\n[<0>] eeh_event_handler+0xf8/0x190\n[<0>] kthread+0x194/0x1b0\n[<0>] start_kernel_thread+0x14/0x18\n\nThe issue is seen for cases where the errors are detected on the PHB\ndirectly AND|OR for devices where the driver error_detected() returns\nPCI_ERS_RESULT_NEED_RESET, and driver being not EEH sensitive(i.e no\nerror handlers like slot_reset(), resume() etc defined)."
}
],
"lastModified": "2026-10-03T11:18:19.963",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}