Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci): Every write to a device's reset_method sysfs attribute that contains no space leaks the
Impact
Every write to a device's reset_method sysfs attribute that contains no space leaks the buffer it allocated, because strsep() has already nulled the pointer that the free uses. The leak is unbounded and driven entirely by the writer, so a loop over that attribute grows kernel memory until the node is under memory pressure - a slow noisy-neighbour outage on a shared host, on the knob that decides how a device is reset between tenants.
Who can reach it
Needs write access to /sys/bus/pci/devices/<dev>/reset_method, which is root-owned - so host root, or a privileged container with /sys mounted writable. Not reachable by a plain tenant container, not reachable from a guest, and not reachable over the fabric. The reason it is worth carrying is the surface rather than the severity: reset_method is the control that determines which reset a device gets when it is reclaimed from one tenant and handed to the next, and it should not be writable from anything a tenant runs.
What to do
Boot a kernel where reset_method_store() iterates over a separate temporary pointer so the original allocation is still freed. Interim: ensure /sys is mounted read-only in containers and that no tenant workload runs with privileges to write PCI sysfs attributes.
References
Related entries
- Linux kernel (drivers/pci): Pci_bus_lock() locked every device on the bus except the bridge itself, so a secondary busCVE-2024-46750 · Linux kernel (drivers/pci)High
- Linux kernel (drivers/pci): The PCI slot-lock failure path releases a lock the caller never took, which at best warnsCVE-2026-43211 · Linux kernel (drivers/pci)High
- Linux kernel (drivers/pci): The option-ROM parser trusts the header and data-structure offsets it reads out of theCVE-2026-72487 · Linux kernel (drivers/pci)High
- Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore pathCVE-2026-64460 · Linux kernel (drivers/pci)High
- Linux kernel (drivers/pci): A Downstream Port Containment event and a device removal happening at the same time leaveCVE-2024-42302 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): A pci_slot holds an uncounted pointer to the pci_bus below it, and on hot removal the busCVE-2024-53194 · Linux kernel (drivers/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.