Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci): The DOE state machine signals the caller's completion before destroying the work_struct
Impact
The DOE state machine signals the caller's completion before destroying the work_struct that lives on the caller's stack, so the workqueue can still be touching a stack frame the caller has already left. DOE is the mailbox that carries CMA/SPDM device attestation and IDE link-encryption negotiation, which makes this a race in exactly the machinery a confidential-GPU deployment relies on to decide whether a device is trustworthy.
Who can reach it
Host-side only, on nodes where a device exposes a DOE mailbox and something drives it - CXL, device attestation (CMA/SPDM), or IDE key exchange. There is no tenant-facing entry point: the race is between the DOE workqueue and the kernel thread that submitted the task, and its timing is influenced by how slowly the device answers, so a slow or deliberately laggy device shifts the window. Nodes with no DOE-capable device, or with attestation/IDE unused, never execute the path.
What to do
Update to 6.1.53 / 6.3 or later, where the work struct is destroyed before the completion is signalled. Interim: on affected kernels avoid driving DOE in production - leave CMA/SPDM attestation and IDE negotiation disabled until patched rather than running them against untrusted devices.
References
Related entries
- Linux kernel (drivers/pci): Enabling or disabling SR-IOV virtual functions was not serialised against PCI hotplug, soCVE-2025-40219 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): When setting up an SR-IOV virtual function fails partway through, the half-initialised VFCVE-2025-22092 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): A failed mmap of peer-to-peer DMA memory leaks the pgmap reference it took, and the leak isCVE-2026-45880 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): When the kernel coalesces two adjacent host-bridge apertures it invalidates the absorbedCVE-2023-53814 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Pci_device_is_present() read the Vendor/Device ID directly, which always reads as all-onesCVE-2022-50636 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Every write to a device's reset_method sysfs attribute that contains no space leaks theCVE-2024-56745 · Linux kernel (drivers/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.