Junglewise Threat Intelligence

CVE-2026-64254: Linux Linux kernel double unmap in NTB EPF driver

CVE-2026-64254 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Non-Transparent Bridge (NTB) driver. This issue occurs during the removal of hardware components, where the system incorrectly attempts to release memory resources that are shared between different functions. While this primarily results in system warnings and potential instability during driver unloading, it represents a flaw in how the kernel manages hardware memory mappings.

Technical details

A vulnerability in the Linux kernel NTB EPF driver (drivers/ntb/hw/epf/ntb_hw_epf.c) stems from an incorrect teardown path in ntb_epf_deinit_pci(). When BAR_PEER_SPAD and BAR_CONFIG share a single PCI Base Address Register (BAR), the driver attempts to call pci_iounmap() on the same I/O memory region twice, once with an offset. This triggers a kernel warning in mm/vmalloc.c (vunmap) because it attempts to unmap a non-existent or already unmapped virtual memory area. An attacker with local administrative privileges could potentially exploit this during module unloading to cause kernel instability. The issue has been resolved by ensuring pci_iounmap() is only called when the registers reside in different BARs.

Affected products

  • Linux Linux 6.0 to 6.1.177, 6.6.144, 6.12.95

Timeline

  • 2026-03-04: other: Patch authored
  • 2026-07-24: advisory: CVE published

References