Database/Kernel, userspace & hypervisor
Linux kernel (drivers/bus/fsl-mc): The fsl-mc bus read its driver_override string without holding the device lock, so
Impact
The fsl-mc bus read its driver_override string without holding the device lock, so the string can be freed underneath a concurrent probe - a use-after-free in the exact mechanism used to force a device onto vfio-fsl-mc for passthrough. A corrupted override can also land a device on the wrong driver, meaning a device the operator intended to hand to a tenant instead binds to a host driver, or the reverse.
Who can reach it
Needs host root: writing /sys/bus/fsl-mc/devices/*/driver_override while a driver bind is in flight. This is the operator's own passthrough-provisioning path, not a tenant surface - the risk is an automation race in node preparation, plus anything that gets root on the host. Hardware-conditional: NXP DPAA2 / fsl-mc platforms only, not x86 or standard Arm server nodes.
What to do
Update to a stable kernel carrying commits 4911b836 / 8139ce66 on fsl-mc platforms. Interim: serialize driver_override writes against bind/unbind in your node-provisioning tooling. No action on x86 or Arm server fleets.
References
Related entries
- Linux kernel (drivers/pci): The PCI bus match callback read driver_override without the device lock, so the overrideCVE-2026-53120 · Linux kernel (drivers/pci)Medium
- Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handling: A guest raises alignment-checkCVE-2015-5307 · Linux KVM (arch/x86/kvm/svm.c, vmx.c) and Xen 4.3.x-4.6.x - #AC exception handlingMedium
- Xen PCI passthrough - device memory/IO decoding and host memory initialisation: With memory and I/O decoding leftCVE-2015-8553 · Xen PCI passthrough - device memory/IO decoding and host memory initialisationMedium
- IBM GPFS kernel module (mmap path): An unprivileged user panics the kernel on a GPFS node just by mmap-ing a file onCVE-2018-1782 · IBM GPFS kernel module (mmap path)Medium
- Linux kernel (arch/x86/kvm): The guard against accessing bytes 4-15 of an emulated APIC register was dropped, andCVE-2021-47255 · Linux kernel (arch/x86/kvm)Medium
- Intel CPU (Downfall / GDS): Downfall: Gather Data Sampling leaks AVX gather-instruction data across SMT siblingsCVE-2022-40982 · Intel CPU (Downfall / GDS)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.