Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci/endpoint/functions): The NTB endpoint function drivers never checked whether their workqueue
Impact
The NTB endpoint function drivers never checked whether their workqueue was actually created, so a failed allocation leaves a NULL pointer that is later handed to queue_work() during endpoint controller init - a NULL dereference that panics the machine at link-up time rather than failing the bind cleanly.
Who can reach it
Endpoint mode with the NTB (non-transparent bridge) function driver bound, plus an allocation failure at bind time - so realistically a memory-pressured endpoint device, not a targeted attack. The dereference itself lands in epf_ntb_epc_init(), which runs when the connected host brings the link up. Inert on a conventional GPU server; relevant to NTB-based host-to-host interconnect hardware.
What to do
Update to a kernel carrying the fix (no fixed_in published; stable commits below). Interim: do not bind the NTB endpoint function drivers on memory-constrained endpoint devices, and keep headroom so the allocation succeeds.
References
Related entries
- Linux kernel (drivers/pci/endpoint/functions): When BAR allocation fails, the endpoint test function frees the backingCVE-2025-38069 · Linux kernel (drivers/pci/endpoint/functions)Medium
- Linux kernel (drivers/pci/endpoint/functions): The endpoint test function releases DMA channels it may never haveCVE-2025-40032 · Linux kernel (drivers/pci/endpoint/functions)Medium
- QEMU: signed/unsigned mismatch in vhost inflight migration state overruns the mmap-backed regionCVE-2026-6426 · QEMU vhost inflight migration (VMS_VBUFFER destination size handling)Medium
- Xen: x86 PV guest keeps a stale TLB entry to a freed page and can write it after scrubbingCVE-2026-79603 · Xen hypervisor (x86 PV guest page free / TLB flush window)Medium
- Linux kernel (drivers/iommu/amd): The AMD-Vi PPR (peripheral page request) notifier looked up the faulting PCI deviceCVE-2022-50505 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.