CVE-2026-98142
In the Linux kernel, the following vulnerability has been resolved:
drm/cirrus-qemu: Validate BAR0 size during probe
The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate framebuffer sizes. However, during PCI probe, the driver mapped BAR0 without verifying that its size matches `CIRRUS_VRAM_SIZE`.
If a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the mapped VRAM will be smaller than expected. Because validation checks assume 4 MB VRAM, framebuffers larger than the mapped memory can be created.
When the display plane is updated (e.g. during release), `cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to VRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory causes a supervisor write page fault:
Leer descripción completaMostrar menos
Fix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource is not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.
Detalles técnicos trazas, registros y código del informe original
BUG: unable to handle page fault for address: ffffc9000389c000 ... RIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110 ... Call Trace: <TASK> iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline] drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442 cirrus_primary_plane_helper_atomic_update+0x98a/0xb00 drivers/gpu/drm/tiny/cirrus-qemu.c:358 drm_atomic_helper_commit_planes+0x626/0xea0 drivers/gpu/drm/drm_atomic_helper.c:3038 drm_atomic_helper_commit_tail+0x60/0x510 drivers/gpu/drm/drm_atomic_helper.c:1989 commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074 drm_atomic_helper_commit+0xa77/0xb10 drivers/gpu/drm/drm_atomic_helper.c:2312
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c
- https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f
- https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6
- https://git.kernel.org/stable/c/2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e
- https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98142",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
"lessThan": "2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e",
"versionType": "git"
},
{
"status": "affected",
"version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
"lessThan": "0b5084a1f070ad1fc34e11945644ae034bbc774c",
"versionType": "git"
},
{
"status": "affected",
"version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
"lessThan": "26bd90c886218f36c9adeab206b0e27b4384e2f6",
"versionType": "git"
},
{
"status": "affected",
"version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
"lessThan": "144f51cd0ccc3ad47a6099917b7bb535611fb18f",
"versionType": "git"
},
{
"status": "affected",
"version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
"lessThan": "92312d333bf700798f92f30406c721bce87506f3",
"versionType": "git"
}
],
"programFiles": [
"drivers/gpu/drm/tiny/cirrus-qemu.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/gpu/drm/tiny/cirrus-qemu.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:45.710",
"references": [
{
"url": "https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Undergoing Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/cirrus-qemu: Validate BAR0 size during probe\n\nThe `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate\nframebuffer sizes. However, during PCI probe, the driver mapped BAR0\nwithout verifying that its size matches `CIRRUS_VRAM_SIZE`.\n\nIf a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the\nmapped VRAM will be smaller than expected. Because validation checks assume\n4 MB VRAM, framebuffers larger than the mapped memory can be created.\n\nWhen the display plane is updated (e.g. during release),\n`cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to\nVRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory\ncauses a supervisor write page fault:\n\nBUG: unable to handle page fault for address: ffffc9000389c000\n...\nRIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110\n...\nCall Trace:\n <TASK>\n iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]\n drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442\n cirrus_primary_plane_helper_atomic_update+0x98a/0xb00\n drivers/gpu/drm/tiny/cirrus-qemu.c:358\n drm_atomic_helper_commit_planes+0x626/0xea0\n drivers/gpu/drm/drm_atomic_helper.c:3038\n drm_atomic_helper_commit_tail+0x60/0x510\n drivers/gpu/drm/drm_atomic_helper.c:1989\n commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074\n drm_atomic_helper_commit+0xa77/0xb10\n drivers/gpu/drm/drm_atomic_helper.c:2312\n\nFix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource\nis not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less."
}
],
"lastModified": "2026-10-03T11:18:36.573",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}