CVE-2026-68317 PUBLISHED

pds_core: fix auxiliary device add/del races

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

pds_core: fix auxiliary device add/del races

Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler. They serialize on config_lock, but neither guards the slot under it correctly.

add() registers and stores a new auxiliary device without first checking the slot, so a second add of an already-populated slot leaks the first device. del() makes that check outside config_lock, so two concurrent dels can both pass it; the first clears the slot, and the second dereferences a NULL pointer.

Check and update the slot under config_lock in both paths.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0861fccd43b8bafb533d97308862d20b7db3a2ad to 646b58b543f3bb1641e9123b75ff7799fe7b42f1 (excl.)
  • affected from f41e27b746241e57d968d1d61c008322338ca258 to ef194751fed50cf3452017b63f00142a0ab40c70 (excl.)
  • affected from b699bdc720c0255d1bb76cecba7382c1f2107af5 to cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518 (excl.)
  • affected from b699bdc720c0255d1bb76cecba7382c1f2107af5 to bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454 (excl.)
  • affected from b699bdc720c0255d1bb76cecba7382c1f2107af5 to bfa33cd513c7ceb93c5a4c30e5662acd73c0a916 (excl.)
  • Version fec5f7af1d5f64a38f9224cd27b274d1af55a7ed is affected
  • affected from 6.6.90 to 6.6.148 (excl.)
  • affected from 6.12.28 to 6.12.101 (excl.)
  • affected from 6.14.6 to 6.15 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.15 is affected
  • unaffected from 0 to 6.15 (excl.)
  • unaffected from 6.6.148 to 6.6.* (incl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References