All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-80867: alpha/PCI: Add security_locked_down() check to pci_mmap_resource()
@ 2026-09-04 16:46 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 16:46 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

alpha/PCI: Add security_locked_down() check to pci_mmap_resource()

Currently, Alpha's pci_mmap_resource() does not check
security_locked_down(LOCKDOWN_PCI_ACCESS) before allowing userspace to mmap
PCI BARs.

The generic version has had this check since commit eb627e17727e ("PCI:
Lock down BAR access when the kernel is locked down") to prevent DMA
attacks when the kernel is locked down.

Add the same check to Alpha's pci_mmap_resource().

The Linux kernel CVE team has assigned CVE-2026-80867 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 5.10.261 with commit 6e368485a1ac19fbde0a8b6a332d4545ae72a8ac
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 5.15.212 with commit ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 6.1.178 with commit c3234efe21d4198945492cf7dba6859476f0f6ff
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 6.6.145 with commit 4de5ff924c0a8ef8166c1a68af9087826e1e8d61
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 6.12.97 with commit 85f966b1120874fe530edec50d28373ceb06ebcd
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 6.18.40 with commit 94defb18ac792fd16407d5a52ad0d3f5055c4b43
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 7.1.5 with commit 257b55dc3d18d7ef01f62a8ff7317871f7597e28
	Issue introduced in 5.4 with commit eb627e17727ebeede70697ae1798688b0d328b54 and fixed in 7.2 with commit 78a228f0aa0e9eba31955950c8a40a9945e2c8bb

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-80867
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	arch/alpha/kernel/pci-sysfs.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/6e368485a1ac19fbde0a8b6a332d4545ae72a8ac
	https://git.kernel.org/stable/c/ed2cd1fee0ed16a1c2dff49175e65c641eb8ae2b
	https://git.kernel.org/stable/c/c3234efe21d4198945492cf7dba6859476f0f6ff
	https://git.kernel.org/stable/c/4de5ff924c0a8ef8166c1a68af9087826e1e8d61
	https://git.kernel.org/stable/c/85f966b1120874fe530edec50d28373ceb06ebcd
	https://git.kernel.org/stable/c/94defb18ac792fd16407d5a52ad0d3f5055c4b43
	https://git.kernel.org/stable/c/257b55dc3d18d7ef01f62a8ff7317871f7597e28
	https://git.kernel.org/stable/c/78a228f0aa0e9eba31955950c8a40a9945e2c8bb

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-04 16:50 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 16:46 CVE-2026-80867: alpha/PCI: Add security_locked_down() check to pci_mmap_resource() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.