Executive brief
A vulnerability was identified in the Linux kernel's Switchtec Non-Transparent Bridge (NTB) driver. This component is used for high-speed data transfer between different computer systems. An attacker with local access could exploit this flaw to cause a system crash or potentially access sensitive information from the system's memory.
Technical details
A shift-out-of-bounds vulnerability exists in the ntb_hw_switchtec driver within the Linux kernel. The root cause is an unchecked call to rounddown_pow_of_two() when the number of Memory Window (MW) Look Up Tables (LUT) is configured to zero. In such scenarios, the mathematical operation results in undefined behavior. A local attacker with low privileges can trigger this condition to cause a denial of service (system crash) or an out-of-bounds read (CWE-125). The issue has been patched across multiple stable kernel branches by adding a conditional check to ensure the value is non-zero before performing the power-of-two calculation.
Affected products
- Linux Linux Kernel 4.15 to 5.10.251, 5.11 to 5.15.201, 5.16 to 6.1.164, 6.2 to 6.6.127, 6.7 to 6.12.74, 6.13 to 6.18.15, 6.19 to 6.19.5
Timeline
- 2026-05-06: disclosed
- 2026-05-06: advisory
- 2026-02-20: patched: Initial patch committed to stable tree
References
- https://git.kernel.org/stable/c/186615f8855a0be4ee7d3fcd09a8ecc10e783b08
- https://git.kernel.org/stable/c/1a867d0d79a4a570a33f2f433919ad2bd7a27b67
- https://git.kernel.org/stable/c/2e4d5e8d86a969318340be95470bb76e52392082
- https://git.kernel.org/stable/c/5590cd04d6845c01a6bad985a491c58af6fb5389
- https://git.kernel.org/stable/c/a11d03d116eef138a7249202bd772c8e61915aec
- https://git.kernel.org/stable/c/a133e3caf844a3f56b6eef89ddaa66115874f6bd
- https://git.kernel.org/stable/c/d0559d07afabfddaaded6a61a16154486b956764