Executive brief
A vulnerability in the Linux kernel's PCI subsystem can cause a system deadlock when managing virtualized network or storage devices. By performing specific hardware configuration commands, a local user could trigger a permanent system freeze, leading to a total loss of availability for the affected server. This impact is particularly relevant for environments using SR-IOV for high-performance virtualization.
Technical details
A deadlock exists in the Linux kernel's PCI/IOV implementation due to recursive acquisition of the 'pci_rescan_remove_lock'. The issue occurs when 'sriov_del_vfs()' is invoked as part of the 'pci_stop_and_remove_bus_device()' path, which already holds the lock. An attacker with local access to sysfs can trigger this by enabling SR-IOV virtual functions and then attempting to remove the physical device. This results in a kernel hang (deadlock). The fix involves reverting the commit that introduced the improper locking mechanism. Patches have been released across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.4.301 to 5.5, 5.10.246 to 5.10.252, 5.15.195 to 5.15.202, 6.1.157 to 6.1.165, 6.6.113 to 6.6.128, 6.12.54 to 6.12.75, 6.17.4 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: advisory: CVE-2026-43147 published by NVD
- 2025-12-16: patched: Initial patch authored by Niklas Schnelle
References
- https://git.kernel.org/stable/c/0de341b2365bad430aade0853fe09c2cbe468f59
- https://git.kernel.org/stable/c/2fa119c0e5e528453ebae9e70740e8d2d8c0ed5a
- https://git.kernel.org/stable/c/40f67686a5002c0c322fac918406bbc8d9c2ec2f
- https://git.kernel.org/stable/c/58677783c89681871077f50a7042b0c6380c4fd8
- https://git.kernel.org/stable/c/639265296fe6ee21b6f00e00ee2bab65f3b07252
- https://git.kernel.org/stable/c/83651d37474c762920e345a3a0828f975ca4d732
- https://git.kernel.org/stable/c/d47f27e145f8bd13f3c230da5e3af29225b4a2f7