Executive brief
A vulnerability in the Linux kernel's Switchtec Non-Transparent Bridge (NTB) driver could allow a local user to cause a system crash or potentially access sensitive kernel memory. The issue occurs when the system is configured with a high number of memory windows, exceeding internal limits. This affects high-performance computing environments using Switchtec PCIe switches for inter-processor communication.
Technical details
An array-index-out-of-bounds access vulnerability (CWE-125) exists in drivers/ntb/hw/mscc/ntb_hw_switchtec.c within the switchtec_ntb_init_shared function. The root cause is a lack of bounds checking on the 'idx' variable, which is calculated based on the number of direct and Look-Up Table (LUT) memory windows (MW). If the combined number of windows exceeds the MAX_MWS constant, the driver attempts to write to an invalid index in the mw_sizes array. This can be triggered during driver initialization or reconfiguration. The fix introduces a check to ensure 'idx' does not exceed MAX_MWS, terminating the loop and logging an error if an invalid configuration is detected.
Affected products
- Linux Linux Kernel 4.15 to 5.10.252, 5.11 to 5.15.202, 5.16 to 6.1.165, 6.2 to 6.6.128, 6.7 to 6.12.75, 6.13 to 6.18.16, 6.19 to 6.19.6
Timeline
- 2026-05-06: advisory: Initial CVE publication
- 2026-03-04: patched: Fix committed to various stable kernel branches
References
- https://git.kernel.org/stable/c/0e930420945106151c6eb3d7837b4e6154e9b144
- https://git.kernel.org/stable/c/2346856b74823a2a78109002e479a3d02526a9ce
- https://git.kernel.org/stable/c/348e1ac9ad983ed7e62de14e1daf47f1695a4ce9
- https://git.kernel.org/stable/c/47ce292dd45dc689747c40603222691638919189
- https://git.kernel.org/stable/c/740945de896021b9a859e71f38f6aea72a6393cf
- https://git.kernel.org/stable/c/85c9daa1f8319bbb3dfee71dc6a2f969cd3b4c92
- https://git.kernel.org/stable/c/c8ba7ad2cc1c7b90570aa347b8ebbe279f1eface