CVE-2026-64254
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
When BAR_PEER_SPAD and BAR_CONFIG share one PCI BAR, the module teardown path ends up calling pci_iounmap() on the same iomem with some offset, which is unnecessary and triggers a kernel warning like the following:
Trying to vunmap() nonexistent vm area (0000000069a5ffe8) WARNING: mm/vmalloc.c:3470 at vunmap+0x58/0x68, CPU#5: modprobe/2937 […] Call trace: vunmap+0x58/0x68 (P) iounmap+0x34/0x48 pci_iounmap+0x2c/0x40 ntb_epf_pci_remove+0x44/0x80 [ntb_hw_epf] pci_device_remove+0x48/0xf8 device_remove+0x50/0x88 device_release_driver_internal+0x1c8/0x228 driver_detach+0x50/0xb0 bus_remove_driver+0x74/0x100 driver_unregister+0x34/0x68 pci_unregister_driver+0x34/0xa0 ntb_epf_pci_driver_exit+0x14/0xfe0 [ntb_hw_epf] […]
Fix it by unmapping only when PEER_SPAD and CONFIG use difference bars.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < eb47b9bffd07a47b84910847cb5ea066ce184055 | affected |
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < 06f6dd2ff2bd07eaf7178a807407ff27e85122b4 | affected |
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < a4be4a1308f02bff79a30eea2d04ead5b63685f2 | affected |
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < 81371dbd23601f67f01372817fdbab42c5601e43 | affected |
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < 9764a786ba98db58f0725913c369e721253aba33 | affected |
| Linux | Linux | e75d5ae8ab88b7ffb3d1d56124b003f3555f74b4 < d876153680e3d721d385e554def919bce3d18c74 | affected |
| Linux | Linux | 6.0 | affected |
| Linux | Linux | 0 < 6.0 | unaffected |
| Linux | Linux | 6.1.177 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.144 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.95 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.38 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.3 <= 7.1.* | unaffected |
| Linux | Linux | 7.2-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/eb47b9bffd07a47b84910847cb5ea066ce184055
- https://git.kernel.org/stable/c/06f6dd2ff2bd07eaf7178a807407ff27e85122b4
- https://git.kernel.org/stable/c/a4be4a1308f02bff79a30eea2d04ead5b63685f2
- https://git.kernel.org/stable/c/81371dbd23601f67f01372817fdbab42c5601e43
- https://git.kernel.org/stable/c/9764a786ba98db58f0725913c369e721253aba33
- https://git.kernel.org/stable/c/d876153680e3d721d385e554def919bce3d18c74
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.