« Volver al listado

CVE-2026-98142

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

drm/cirrus-qemu: Validate BAR0 size during probe

The `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate framebuffer sizes. However, during PCI probe, the driver mapped BAR0 without verifying that its size matches `CIRRUS_VRAM_SIZE`.

If a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the mapped VRAM will be smaller than expected. Because validation checks assume 4 MB VRAM, framebuffers larger than the mapped memory can be created.

When the display plane is updated (e.g. during release), `cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to VRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory causes a supervisor write page fault:

Leer descripción completaMostrar menos

Fix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource is not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.

Detalles técnicos trazas, registros y código del informe original
BUG: unable to handle page fault for address: ffffc9000389c000
...
RIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110
...
Call Trace:
 <TASK>
 iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]
 drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442
 cirrus_primary_plane_helper_atomic_update+0x98a/0xb00
 drivers/gpu/drm/tiny/cirrus-qemu.c:358
 drm_atomic_helper_commit_planes+0x626/0xea0
 drivers/gpu/drm/drm_atomic_helper.c:3038
 drm_atomic_helper_commit_tail+0x60/0x510
 drivers/gpu/drm/drm_atomic_helper.c:1989
 commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074
 drm_atomic_helper_commit+0xa77/0xb10
 drivers/gpu/drm/drm_atomic_helper.c:2312

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98142",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
              "lessThan": "2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
              "lessThan": "0b5084a1f070ad1fc34e11945644ae034bbc774c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
              "lessThan": "26bd90c886218f36c9adeab206b0e27b4384e2f6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
              "lessThan": "144f51cd0ccc3ad47a6099917b7bb535611fb18f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ab3e023b1b4c9887c9f0f761b47f3f0516bd3434",
              "lessThan": "92312d333bf700798f92f30406c721bce87506f3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/tiny/cirrus-qemu.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.2"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.2",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/gpu/drm/tiny/cirrus-qemu.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:45.710",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a0e7bcff3fa63e7309d2b39e18af59eb8ef2b6e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/cirrus-qemu: Validate BAR0 size during probe\n\nThe `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate\nframebuffer sizes. However, during PCI probe, the driver mapped BAR0\nwithout verifying that its size matches `CIRRUS_VRAM_SIZE`.\n\nIf a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the\nmapped VRAM will be smaller than expected. Because validation checks assume\n4 MB VRAM, framebuffers larger than the mapped memory can be created.\n\nWhen the display plane is updated (e.g. during release),\n`cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to\nVRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory\ncauses a supervisor write page fault:\n\nBUG: unable to handle page fault for address: ffffc9000389c000\n...\nRIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110\n...\nCall Trace:\n <TASK>\n iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]\n drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442\n cirrus_primary_plane_helper_atomic_update+0x98a/0xb00\n drivers/gpu/drm/tiny/cirrus-qemu.c:358\n drm_atomic_helper_commit_planes+0x626/0xea0\n drivers/gpu/drm/drm_atomic_helper.c:3038\n drm_atomic_helper_commit_tail+0x60/0x510\n drivers/gpu/drm/drm_atomic_helper.c:1989\n commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074\n drm_atomic_helper_commit+0xa77/0xb10\n drivers/gpu/drm/drm_atomic_helper.c:2312\n\nFix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource\nis not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less."
    }
  ],
  "lastModified": "2026-10-03T11:18:36.573",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}