Database/Kernel, userspace & hypervisor
Linux kernel (drivers/pci): An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore path
Impact
An SR-IOV device that stops answering config reads makes the VF Resizable BAR restore path read index 7 out of a 6-entry BAR-size array, so the host kernel reads past the end of the VF's resource table and then restores BAR windows from whatever it found. The reported case is exactly the fleet shape that matters - an NVIDIA GPU that stopped responding on a power-state exit - and the vendor scores it scope-changed, meaning the bad restore reaches beyond the failing device.
Who can reach it
Host-side, on a node with SR-IOV enabled and VFs created on a device that supports VF Resizable BAR (NVIDIA GPUs among them). It fires when pci_restore_state() runs while the device is unreachable and config reads return all-ones - a wedged or power-state-stuck GPU, a link that dropped, or a device a tenant has driven into a bad state through its assigned VF. A tenant does not call it directly; a tenant that can hang its assigned device can make the host walk into it.
What to do
Boot a kernel with the sriov_restore_vf_rebar_state() error-response guard. Interim: on nodes where you do not need them, disable SR-IOV VFs (sriov_numvfs = 0) so the VF ReBAR restore path is never entered, and drain nodes whose GPUs are logging config-read failures or GC6/power-state exit errors rather than letting the recovery path run.
References
Related entries
- Linux kernel (drivers/pci): A Downstream Port Containment event and a device removal happening at the same time leaveCVE-2024-42302 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): A pci_slot holds an uncounted pointer to the pci_bus below it, and on hot removal the busCVE-2024-53194 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): The PCI bus match callback read driver_override without the device lock, so the overrideCVE-2026-53120 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Pm_runtime_get_sync() does not wait for an already-running .runtime_idle() callback, so aCVE-2024-35809 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Tearing down a PF that still has SR-IOV VFs takes pci_rescan_remove_lock recursively andCVE-2026-43147 · Linux kernel (drivers/pci)Medium
- Linux kernel (drivers/pci): Pci_dev_lock() and the sysfs SR-IOV path took the device lock and the config-space accessCVE-2022-49434 · Linux kernel (drivers/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.