* CVE-2026-80917: PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
@ 2026-09-09 16:13 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-09 16:13 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
On 32-bit systems the config space is too large to ioremap in one go, so
pci_ecam_create() maps each bus segment separately and relies on the
->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in
cfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for
every config access.
The generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus
and ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c
do not. As a result, on a 32-bit host using "pci-host-cam-generic" the
per-bus mapping is never set up and the first config read dereferences a
NULL base, crashing during bus enumeration:
Unable to handle kernel NULL pointer dereference at virtual address 00000800
Oops [#1]
CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43
Hardware name: Digilent Nexys-Video-A7 RV32 (DT)
epc : pci_generic_config_read+0x40/0xb0
ra : pci_generic_config_read+0x2c/0xb0
[<c038db9c>] pci_generic_config_read+0x40/0xb0
[<c038da04>] pci_bus_read_config_dword+0x50/0xb0
[<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec
[<c039245c>] pci_scan_single_device+0xa4/0x11c
[<c0392570>] pci_scan_slot+0x9c/0x23c
[<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4
[<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8
[<c0393e54>] pci_host_probe+0x20/0xc8
[<c03bc6f4>] pci_host_common_probe+0x144/0x1e4
Fix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.
Since pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,
move the CAM ops definition there as pci_generic_cam_ops (mirroring
pci_generic_ecam_ops) and export it for pci-host-generic.c to reference.
[mani: removed timestamp from log]
The Linux kernel CVE team has assigned CVE-2026-80917 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 5.15.218 with commit 5e52eb0290f66ba0732956dcb1e365b5ca3c5108
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 6.1.185 with commit baf9b0383ff770fdff123d3a832f3a99641d96dd
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 6.6.154 with commit 8d08713ec83a18526d1ed1fd5f0d2b901d103a10
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 6.12.106 with commit 74456843f18ba7f3045974d7e8b88ab993152b8c
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 6.18.47 with commit 0c55707bd5d0d7670704cfd0dda933809b052f67
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 7.1.11 with commit a199293f3038db8d31d47aa60f1e18272cd82354
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 7.2.1 with commit 0916948026f623844acd08888f7cbedbf1c48d6b
Issue introduced in 5.14 with commit 8fe55ef23387ce3c7488375b1fd539420d7654bb and fixed in 7.3-rc1 with commit 008cb88edb41f3c7c8e0ed763ff9f26719830984
Issue introduced in 5.12.19 with commit 0b5877a1aeacdbf32b3bea91326592004ec7806f
Issue introduced in 5.13.4 with commit a037ebbe72a4f98495b193112e2b2000e5e09eb5
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80917
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/pci/controller/pci-host-generic.c
drivers/pci/ecam.c
include/linux/pci-ecam.h
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108
https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd
https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10
https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c
https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67
https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354
https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b
https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-09 16:13 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09 16:13 CVE-2026-80917: PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.