Database/Kernel, userspace & hypervisor
Linux PCI sysfs: BAR resize via resourceN_resize had no CAP_SYS_ADMIN check
Impact
Writing the resourceN_resize sysfs attribute reprograms a PCI device's BAR size, and the kernel gated it only on file permissions rather than on CAP_SYS_ADMIN. Anyone who could open that file for writing could change the BAR layout of a live device and disrupt the driver bound to it. That matters on GPU and DPU nodes because resizable BARs are exactly what large-VRAM accelerators and NICs use, and a resize under an active driver is a device-level disruption that typically ends in a node reboot, not a clean recovery. In practice the sysfs file is root-owned on a default system, so exposure depends on whether anything in your stack loosens those permissions or hands the file to a less privileged agent.
Who can reach it
Local, and only for a user or container that has been given write access to /sys/bus/pci/devices/*/resourceN_resize. Default permissions already restrict this to root, so this is a defence-in-depth fix for hosts where sysfs ownership has been relaxed.
What to do
Pick up a stable kernel with the CAP_SYS_ADMIN check (three stable commits listed) on your next kernel roll and reboot the node. In the meantime confirm nothing but root can write PCI resize attributes on your hosts - that check costs nothing and closes the reachable case. No fixed distro version is named in the record.
References
Related entries
- Linux qla2xxx: double free and NULL dma_pool use when adapter memory allocation fails at probeCVE-2026-97532 · Linux kernel scsi qla2xxx (qla2x00_mem_alloc error path, dangling pointers)Unscored
- Linux qla2xxx: NULL dma_free and mismatched bitmap locking in multiqueue queue teardownCVE-2026-97537 · Linux kernel scsi qla2xxx (multiqueue req/rsp queue teardown, qid bitmap locking)Unscored
- Linux LIO iSCSI target: LUN_RESET on a WRITE_PENDING command deadlocks the target worker threadCVE-2026-97951 · Linux kernel SCSI target iSCSI frontend (aborted WRITE_PENDING dataout handling)Unscored
- Linux cgroup: task iterator can resurrect a zero-refcount dying task, giving a use-after-freeCVE-2026-98163 · Linux kernel cgroup task iterator (css_task_iter_next over dying_tasks)Unscored
- Microsoft Hyper-V: vmswitch fails to validate guest OID requestsCVE-2021-28476 · Microsoft Hyper-VCritical
- Incus: instance snapshots bypass restricted.containers.lowlevel, giving command execution on the hostCVE-2026-48751 · Incus (instance snapshots ignore restricted.containers.lowlevel)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.