CVE-2026-98020
In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix cmd_regs access racing BAR unmap on reset
pdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path clear/iounmap cmd_regs without devcmd_lock, and pdsc_legacy_firmware_update()'s download loop derefs cmd_regs after dropping and retaking the lock without re-checking. An FLR concurrent with a devlink flash can unmap cmd_regs under an in-flight devcmd, causing a NULL deref or a write to unmapped MMIO.
Take devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in the download loop. Only the PF maps cmd_regs and runs devcmd, so skip the unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do.
Leer descripción completaMostrar menos
A reset that completes entirely within the unlocked window is not a correctness problem for the image: the device clears its update session, so a resumed download is rejected, and it verifies the staged image before writing a flash slot, reporting PDS_RC_BAD_FW rather than activating it.
pdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The interrupt and start/stop readers of those are quiesced before the unmap by pdsc_fw_down(), which frees the interrupts and tears down the queues. The debugfs readers are not, since those files outlive a reset; that is pre-existing and out of scope here.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/09f831bfe39de5b8026fefb3d106b5cc93272170
- https://git.kernel.org/stable/c/0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9
- https://git.kernel.org/stable/c/2cc697565fd19b5ba2d100cdd4a20dd6d263abc2
- https://git.kernel.org/stable/c/7980325b2f71e3f65c1323c39792e2455da6fab6
- https://git.kernel.org/stable/c/fa31bd14c5042c6315bb2182c963f03ca6e79ca4
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98020",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f6ec6ac9432941ec85a2221c91b1ecfc85680d89",
"lessThan": "0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9",
"versionType": "git"
},
{
"status": "affected",
"version": "e96094c1d11cce4deb5da3c0500d49041ab845b8",
"lessThan": "2cc697565fd19b5ba2d100cdd4a20dd6d263abc2",
"versionType": "git"
},
{
"status": "affected",
"version": "e96094c1d11cce4deb5da3c0500d49041ab845b8",
"lessThan": "fa31bd14c5042c6315bb2182c963f03ca6e79ca4",
"versionType": "git"
},
{
"status": "affected",
"version": "e96094c1d11cce4deb5da3c0500d49041ab845b8",
"lessThan": "09f831bfe39de5b8026fefb3d106b5cc93272170",
"versionType": "git"
},
{
"status": "affected",
"version": "e96094c1d11cce4deb5da3c0500d49041ab845b8",
"lessThan": "7980325b2f71e3f65c1323c39792e2455da6fab6",
"versionType": "git"
},
{
"status": "affected",
"version": "692488941283d72362274620b9abd28109fc459f",
"versionType": "git"
},
{
"status": "affected",
"version": "6.6.16",
"lessThan": "6.6.158",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.7.4",
"lessThan": "6.8",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/ethernet/amd/pds_core/fw.c",
"drivers/net/ethernet/amd/pds_core/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/amd/pds_core/fw.c",
"drivers/net/ethernet/amd/pds_core/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:30.480",
"references": [
{
"url": "https://git.kernel.org/stable/c/09f831bfe39de5b8026fefb3d106b5cc93272170",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0bf9f3bae3c4b1eadb7a2bf63350333db7dac0d9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2cc697565fd19b5ba2d100cdd4a20dd6d263abc2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7980325b2f71e3f65c1323c39792e2455da6fab6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fa31bd14c5042c6315bb2182c963f03ca6e79ca4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix cmd_regs access racing BAR unmap on reset\n\npdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path\nclear/iounmap cmd_regs without devcmd_lock, and\npdsc_legacy_firmware_update()'s download loop derefs cmd_regs after\ndropping and retaking the lock without re-checking. An FLR concurrent\nwith a devlink flash can unmap cmd_regs under an in-flight devcmd,\ncausing a NULL deref or a write to unmapped MMIO.\n\nTake devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in\nthe download loop. Only the PF maps cmd_regs and runs devcmd, so skip\nthe unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do.\n\nA reset that completes entirely within the unlocked window is not a\ncorrectness problem for the image: the device clears its update session,\nso a resumed download is rejected, and it verifies the staged image\nbefore writing a flash slot, reporting PDS_RC_BAD_FW rather than\nactivating it.\n\npdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The\ninterrupt and start/stop readers of those are quiesced before the unmap\nby pdsc_fw_down(), which frees the interrupts and tears down the queues.\nThe debugfs readers are not, since those files outlive a reset; that is\npre-existing and out of scope here."
}
],
"lastModified": "2026-10-03T11:18:25.030",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}