Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/endpoint): Pci_epc_destroy() releases the PCI domain ID using a device object it has already
Impact
Pci_epc_destroy() releases the PCI domain ID using a device object it has already unregistered and freed, so the domain-ID release runs against freed memory. Beyond the use-after-free itself, it releases the WRONG domain ID (the EPC's rather than its parent's), corrupting the kernel's domain-number allocator for every controller that follows.
Who can reach it
Endpoint mode required: the machine must run a PCIe endpoint controller with the EPC core registered. Reached when the EPC is destroyed - controller driver unbind or module unload, which is host root. Not tenant-reachable and inert on a normal GPU host; it matters on DPU/smartNIC style devices that run Linux as the endpoint and whose controller drivers get reloaded.
What to do
Update to 6.12 or later, or take the stable commits below. Interim: avoid unbinding or unloading PCIe endpoint controller drivers on a running system; reboot instead.
References
Related entries
- Linux kernel (drivers/pci/endpoint): The endpoint function core calls list_del() on a structure that is a list HEADCVE-2025-39783 · Linux kernel (drivers/pci/endpoint)Medium
- Linux kernel (drivers/pci/endpoint): Endpoint function sub-groups were created asynchronously by a delayed work itemCVE-2025-71233 · Linux kernel (drivers/pci/endpoint)Medium
- Linux kernel (drivers/vfio/cdx): A tenant can call the interrupt-configuration ioctl with the trigger flags before MSICVE-2026-46034 · Linux kernel (drivers/vfio/cdx)Medium
- OpenSSH client X11 forwarding: a local user can pre-bind the X socket and hijack a forwarded sessionCVE-2026-55655 · OpenSSH client X11 forwarding (abstract UNIX X socket pre-binding)Medium
- Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.x: Proof that interrupt remapping is not a completeCVE-2013-3495 · Intel VT-d interrupt remapping engine as used by Xen 3.3.x-4.3.xMedium
- Xen 3.3.x-4.5.x and Linux kernel through 3.19.1 - PCI command register access for assigned devices: A tenant clears theCVE-2015-2150 · Xen 3.3.x-4.5.x and Linux kernel through 3.19.1 - PCI command register access for assigned devicesMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.