Executive brief
A vulnerability was identified in the Linux kernel's pds_core driver, which manages certain network interface hardware. The driver could incorrectly report that a command succeeded even if the hardware's firmware had crashed or the command had timed out. This failure to properly detect errors could lead to unstable system behavior or prevent the system from automatically recovering from hardware issues.
Technical details
A logic error in the pdsc_devcmd_wait() function within the pds_core driver (drivers/net/ethernet/amd/pds_core/dev.c) causes it to return stale success values from completion registers under error conditions. Specifically, if the firmware crashes, the wait loop terminates with 'running=false', bypassing the error check and returning a stale status. Additionally, during a command timeout, the -ETIMEDOUT error code was being overwritten by a stale status read. These failures prevent the error from propagating to pdsc_devcmd_locked(), which is responsible for triggering the health_work recovery mechanism. The fix introduces explicit checks for the 'running' state and ensures timeout errors are returned immediately.
Affected products
- Linux Linux 6.4 to 6.6.141, 6.12.91, 6.18.33, 7.0.10
Timeline
- 2026-05-15: patched: Initial patch authored
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0e46b6635b03d29807f810c3b415c4755a3f958d
- https://git.kernel.org/stable/c/10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2
- https://git.kernel.org/stable/c/3231aff8ab26111c54e630b1a200fc43a729dd14
- https://git.kernel.org/stable/c/560d559324169fe0583d54c475b5329550a86f71
- https://git.kernel.org/stable/c/784dd2bdc622ed3cc6ef8e113aa1852e252de36f