Database/Kernel, userspace & hypervisor
Linux kernel (drivers/vfio/pci): The disable_idle_d3 power-management flag was a module-wide global that could change
Impact
The disable_idle_d3 power-management flag was a module-wide global that could change out from under devices already bound to vfio-pci, so runtime-PM get/put operations on a passed-through device become unbalanced. An unbalanced PM reference means a device can be dropped into D3hot while a tenant still owns it, or held in D0 forever - device state confusion on the passthrough boundary and a path to refcount underflow.
Who can reach it
Needs host root: loading, unloading, or reloading vfio-pci with a different disable_idle_d3 value, or writing the module parameter through sysfs, while devices are already bound to a vfio-pci variant driver. This is an operator/automation hazard rather than a tenant-reachable one - but it lands directly on devices tenants are actively using.
What to do
Update to a stable kernel carrying commits 332d785f / 654710ef, which latches the flag per device at init. Interim: set disable_idle_d3 once at boot via modprobe.d and never change it or reload vfio-pci while tenant devices are bound.
References
Related entries
- Linux kernel (drivers/vfio/pci): A failed interrupt-context allocation while enabling INTx leaks the IRQ name string.CVE-2024-38632 · Linux kernel (drivers/vfio/pci)Medium
- Linux kernel (drivers/vfio/pci): When a tenant closes its passed-through PCI device, vfio disables the function beforeCVE-2026-53322 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): Vfio-pci exports a dma-buf over BAR memory without confirming those BAR resources wereCVE-2026-64042 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): If vfio-pci device registration fails after the device joined the VGA arbiter, theCVE-2026-64475 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): A tenant races a DisINTx write to emulated config space against a SET_IRQS ioctl, soCVE-2024-26810 · Linux kernel (drivers/vfio/pci)High
- Linux kernel (drivers/vfio/pci): A tenant holding a passthrough PCI device can make the kernel signal an interruptCVE-2024-26812 · Linux kernel (drivers/vfio/pci)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.