Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/controller): The Intel VMD driver guarded config-space access with a lock type that becomes a
Impact
The Intel VMD driver guarded config-space access with a lock type that becomes a sleeping lock under PREEMPT_RT, while the PCI core calls into it with interrupts disabled. Reading config space then sleeps in atomic context - a BUG splat and a wedged CPU on the shared node, reached from an ordinary sysfs read rather than anything privileged.
Who can reach it
The reported call chain starts in sysfs: pci_read_config -> pci_user_read_config_byte -> vmd_pci_read, i.e. a read of /sys/bus/pci/devices/<dev>/config for a device behind Intel VMD. Any local process that can open that file reaches it, including a tenant container with the default sysfs mount. Conditional on two things and inert without both: a PREEMPT_RT kernel, and Intel VMD enabled in BIOS (common on Intel server platforms fronting NVMe).
What to do
Update to a kernel carrying the fix (no fixed_in published; stable commits below). Interim: on PREEMPT_RT nodes, either disable VMD in BIOS or mask sysfs config-space files from tenant containers; on non-RT kernels no action is needed.
References
Related entries
- Linux kernel (drivers/pci/controller): The Hyper-V PCI front-end frees its PCI domain number twice on a probe failureCVE-2026-43097 · Linux kernel (drivers/pci/controller)Medium
- Linux kernel (ksmbd): Use-after-free in ksmbd session logoff (found by an LLM-assisted audit)CVE-2025-37899 · Linux kernel (ksmbd)Medium
- Linux kernel (drivers/iommu/intel): On VT-d scalable mode with VMD enabled, RID2PASID setup fails for devices behindCVE-2022-48916 · Linux kernel (drivers/iommu/intel)Medium
- Linux kernel (drivers/vfio/mdev): If creating an mdev type's sysfs entries partially fails, the parent still registersCVE-2023-52570 · Linux kernel (drivers/vfio/mdev)Medium
- util-linux (wall): WallEscape: escape-sequence injection via wall(1)CVE-2024-28085 · util-linux (wall)Medium
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.