Executive brief
A vulnerability was identified in the Linux kernel's PCI endpoint driver for Non-Transparent Bridges (NTB). The issue involves a redundant resource cleanup process that can cause the system to crash (kernel oops) during specific link operations. This could lead to a denial-of-service condition, impacting system stability and availability.
Technical details
A vulnerability in the Linux kernel's PCI endpoint NTB (Non-Transparent Bridge) function driver (pci-epf-ntb.c) was caused by redundant resource teardown in the epf_ntb_epc_destroy() function. This helper function duplicated teardown actions that were already managed by the caller, leading to a kernel 'oops' (null pointer dereference or similar memory corruption) when .allow_link fails or .drop_link is executed. Additionally, improper EPC device refcounting via pci_epc_put() was identified and corrected. The fix involves removing the redundant helper and ensuring refcounting is correctly tied to the configfs EPC group lifetime. An attacker with local access could potentially trigger this crash to cause a denial of service.
Affected products
- Linux Linux kernel Fixed in versions 3446bed, 65fc57c, 72099f0, 756ca5e, e813c95
Timeline
- 2026-02-26: other: Initial patch authored
- 2026-05-27: advisory: NVD advisory published
References
- https://git.kernel.org/stable/c/3446beddba450c8d6f9aca2f028712ac527fead3
- https://git.kernel.org/stable/c/65fc57c8b8f0b31be62be291cb1bb01755cec85d
- https://git.kernel.org/stable/c/72099f015d3c77bf2eb703d1aab113bd7a60915a
- https://git.kernel.org/stable/c/756ca5e7ed22d9045bb4de4c981f9149278d5cd3
- https://git.kernel.org/stable/c/e813c95e4c8edd31599081e6356e20ada30e266d