CVE-2026-53322
Beschrijving NL
In de Linux kernel is de volgende kwetsbaarheid verholpen:
vfio/pci: DMABUF's opruimen voordat de functie wordt uitgeschakeld
Voer bij het afsluiten van het apparaat een vfio_pci_core_close_device() -oproep uit
vfio_pci_dma_buf_cleanup() voordat de functie wordt uitgeschakeld via
vfio_pci_core_disable(). Dit zorgt ervoor dat alle toegang via DMABUFs
ingetrokken voordat de bar's van de functie ontoegankelijk worden. Dit lost een probleem op waarbij, als de functie eerst is uitgeschakeld, een kleine
venster bestaat waarin de MSE van de functie wordt gewist en toch bar's
was nog steeds toegankelijk via de DMABUF. De middelen zouden ook
bevrijd en voor het grijpen door een andere chauffeur.
Origineel (Engels) tonen
In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Clean up DMABUFs before disabling function
On device shutdown, make vfio_pci_core_close_device() call
vfio_pci_dma_buf_cleanup() before the function is disabled via
vfio_pci_core_disable(). This ensures that all access via DMABUFs is
revoked before the function's BARs become inaccessible.
This fixes an issue where, if the function is disabled first, a tiny
window exists in which the function's MSE is cleared and yet BARs
could still be accessed via the DMABUF. The resources would also be
freed and up for grabs by a different driver.