Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci/xe): Resetting a passed-through Intel GPU virtual function that does not support
Impact
Resetting a passed-through Intel GPU virtual function that does not support migration makes the host dereference a NULL migration context and oops in the reset-done callback. The host kernel goes down on a GPU-passthrough node, so one tenant resetting its own card is an outage for every tenant sharing that box.
Who can reach it
The reproducer runs through the sysfs reset attribute, which needs host root, but the same pci_reset_function() path is what runs on VFIO_DEVICE_RESET and on device-fd release - both of which a tenant holding /dev/vfio/<group> drives directly. Conditional on the xe_vfio_pci variant driver being bound to an Intel Xe SR-IOV VF that lacks migration support. Not reachable on NVIDIA-only fleets.
What to do
Update to a stable kernel carrying commits 8fa4113f / 73e53ff1. Interim: on Intel GPU SR-IOV nodes, bind VFs to plain vfio-pci rather than xe_vfio_pci where live migration is not needed, and block tenant-initiated device reset in the VMM.
References
Related entries
- Linux kernel (net/xfrm): The async-event reply buffer was sized without accounting for the interface-ID attribute, soCVE-2026-43107 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/iommu/amd): AMD-Vi hands out the completion-wait sequence number outside the IOMMU lock, soCVE-2026-43220 · Linux kernel (drivers/iommu/amd)Medium
- Linux kernel (net/xfrm): Tearing down an IPTFS security association cancels its hrtimers while holding the very locksCVE-2026-53197 · Linux kernel (net/xfrm)Medium
- Linux kernel (net/smc): Setsockopt() on an SMC socket copies the option value from user memory while holding the socketCVE-2026-53274 · Linux kernel (net/smc)Medium
- OpenSSH client: double free on attacker-controlled DH-GEX parameters crashes the client in FIPS modeCVE-2026-55653 · OpenSSH client (DH-GEX known-group validation in FIPS mode)Medium
- Linux kernel (drivers/iommu/iommufd): A tenant using nested translation can ask iommufd to process a cache-invalidationCVE-2026-64289 · Linux kernel (drivers/iommu/iommufd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.