Executive brief
A vulnerability in the Linux kernel's PCI endpoint driver could allow a local user to cause a system crash. The issue occurs during the cleanup of certain hardware resources, where background tasks are not properly stopped before the memory they use is released. This can lead to a 'kernel panic' or system instability, potentially disrupting operations or causing a denial of service.
Technical details
A race condition exists in the pci-epf-vntb driver within the Linux kernel's PCI endpoint framework. The function epf_ntb_epc_cleanup fails to stop the cmd_handler delayed work before clearing BAR mappings and doorbell resources. If the delayed work executes after these resources have been torn down, it attempts to access invalid memory addresses, resulting in a kernel paging request error (Oops). This is a local denial-of-service vulnerability. The fix involves adding a call to disable_delayed_work_sync() or cancel_delayed_work_sync() at the beginning of the cleanup routine to ensure all background tasks are synchronized and stopped before resource deallocation.
Affected products
- Linux Linux Kernel 6.0 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed: Initial disclosure via kernel.org
- 2026-04-24: advisory: NVD published the CVE record
- 2026-04-22: patched: Patches committed to various stable branches
References
- https://git.kernel.org/stable/c/5999067140c67530a6cb6f41a8471596e60452cb
- https://git.kernel.org/stable/c/6773cc24c004930903a57761132c1e7728907f8f
- https://git.kernel.org/stable/c/9921cce25bfe4021f6e55ca995351eb967165297
- https://git.kernel.org/stable/c/b2eb405bbced3a6e772545e1b74dbde37cee1f8f
- https://git.kernel.org/stable/c/ceb73484e7204f661f770069ecdf35f6e941879c
- https://git.kernel.org/stable/c/d799984233a50abd2667a7d17a9a710a3f10ebe2
- https://git.kernel.org/stable/c/fbb6c353fa2fb5f5f990eda034a1074b0356127e