Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/pcie): The AER subsystem allocates its per-device error-tracking structure without checking
Impact
The AER subsystem allocates its per-device error-tracking structure without checking for failure, then dereferences it unconditionally. If that allocation fails, every subsequent AER access is a NULL dereference and the node panics - so a burst of PCIe errors arriving while the machine is under memory pressure turns into a full node outage for every tenant.
Who can reach it
Precondition is an allocation failure, which is the honest limiter here - but both halves are things a tenant supplies on a busy GPU node. Memory pressure is the steady state on a node packed with tenants, and the error events are generated by the devices themselves: a tenant with a passthrough GPU, NIC or NVMe behind /dev/vfio/* can drive its own device into producing correctable and uncorrectable PCIe errors at will, which is what makes the AER path run in the first place. No host credentials required for the error-generating half.
What to do
Update to a kernel carrying the fix (no fixed_in published; stable commits below). Interim: keep real headroom on nodes so the allocation does not fail, and alert on AER error rates per device so a tenant hammering its passthrough device into an error storm is visible before it matters.
References
Related entries
- Linux kernel (drivers/pci/pcie): PCIe bandwidth control dereferences a bridge's subordinate bus pointer withoutCVE-2025-22031 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state keeps a raw pointer to function 0 of a multi-function device.CVE-2023-53446 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): The ASPM link state of a PCIe switch is freed as soon as ANY function on the upstreamCVE-2024-58093 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/pcie): AER's rate limiter dereferences per-device error state without checking it exists.CVE-2025-40034 · Linux kernel (drivers/pci/pcie)Medium
- Linux kernel (drivers/pci/endpoint): Endpoint function sub-groups were created asynchronously by a delayed work itemCVE-2025-71233 · Linux kernel (drivers/pci/endpoint)Medium
- systemd-oomd: unprivileged local users can kill arbitrary processes via unvalidated IPC pathCVE-2026-15059 · systemd-oomd (IPC API cgroup path validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.