Database/Firmware, BMC & network fabric
Linux kernel PMBus hwmon: type confusion in the alert path reads past the attribute allocation
Impact
pmbus_notify() casts every attribute in the group to struct sensor_device_attribute and reads ->index, but the group also holds pmbus_samples_reg and pmbus_sensor objects that only embed a base device_attribute. For pmbus_samples_reg the index read runs past the end of the allocation, a slab out-of-bounds read; for pmbus_sensor the index overlaps page, phase and reg, so a garbage mask can spuriously match during an alert. This is the driver that reads PSU, VRM and hot-swap controller telemetry on high-power GPU chassis, so the practical consequences are a KASAN splat or bogus power-event notifications rather than a tenant-reachable compromise. No attacker path from a workload is established by the record.
Who can reach it
Not reachable from the network or from a tenant workload. The path runs when a PMBus device on the node's I2C/SMBus raises an alert, on a host that has the pmbus hwmon drivers loaded; influencing it deliberately means control of that bus, which is physical access.
What to do
Pick up a stable kernel with the fix at the next scheduled kernel roll and reboot the node - there is no separate vendor advisory and no live-patch path for this. Nodes that do not load pmbus hwmon drivers have no exposure, which is worth checking before it drives any maintenance window of its own.
References
Related entries
- Linux kernel hns_roce: bonding teardown order leaks resources and leaves a stale netdev notifierCVE-2026-80625 · Linux kernel hns_roce (RoCE bonding resource teardown order)Unscored
- Linux kernel Soft-RoCE: modify_qp frees the rd_atomic array using the new size, writing out of boundsCVE-2026-80863 · Linux kernel RDMA/rxe (free_rd_atomic_resources during modify_qp)Unscored
- Linux kernel rdma_rxe: use-after-free in the responder task when modify_qp swaps the RD-atomic resource arrayCVE-2026-80864 · Linux kernel Soft-RoCE responder (rdma_rxe, IB_QP_MAX_DEST_RD_ATOMIC modify_qp)Unscored
- Linux kernel mlx5_ib: implicit ODP parent mkey re-registered in place, racing its child mkeys and mr->pdCVE-2026-80880 · Linux kernel mlx5_ib implicit ODP (rereg_mr on a parent mkey)Unscored
- Linux tpm_i2c_nuvoton: unbalanced enable_irq() on wait timeout can wedge TPM accessCVE-2026-80930 · Linux kernel tpm_i2c_nuvoton (TPM I2C driver IRQ balance)Unscored
- Linux kernel ipmi_msghandler: work item left scheduled when interface startup fails, freeing live stateCVE-2026-81004 · Linux kernel IPMI message handler (ipmi_msghandler interface startup error path)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.