Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci): The PCI bus match callback read driver_override without the device lock, so the override
Impact
The PCI bus match callback read driver_override without the device lock, so the override string can be freed while a probe is reading it - a use-after-free in the single mechanism a GPU cloud uses to force a card onto vfio-pci for passthrough. Beyond the memory-safety bug, a torn override read means a device can bind to the wrong driver: a card meant for a tenant lands on a host driver, or a host device lands on vfio-pci and becomes reachable from a container.
Who can reach it
Needs host root: writing /sys/bus/pci/devices/<bdf>/driver_override concurrently with a bind, which is exactly what node-provisioning automation does when it flips GPUs and NICs between host drivers and vfio-pci. Not tenant-reachable, but it sits on the provisioning path that decides who owns which device, and the xen-pciback stub is affected the same way.
What to do
Update to a stable kernel carrying commits dfe950d9 / 58a42be0. Interim: serialize driver_override writes against driver bind/unbind in your provisioning tooling - write the override, then bind, never concurrently - and verify the resulting driver binding before offering a device to a tenant.
References
Related entries
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aCVE-2024-35809 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Tearing down a PF that still has SR-IOV VFs takes pci_rescan_remove_lock recursively andCVE-2026-43147 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessCVE-2022-49434 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): The DOE state machine signals the caller's completion before destroying the work_structCVE-2023-54235 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Enabling or disabling SR-IOV virtual functions was not serialised against PCI hotplug, soCVE-2025-40219 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): When setting up an SR-IOV virtual function fails partway through, the half-initialised VFCVE-2025-22092 · Linux kernel (drivers/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.