CVE-2026-64148 (GCVE-0-2026-64148)
Vulnerability from cvelistv5
Published
2026-07-19 15:40
Modified
2026-08-05 12:39
Summary
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery.
Impacted products
Vendor Product Version
Linux Linux Version: 45d76f492938cdc27ddadc16e1e75103f4cfbf56
Version: 45d76f492938cdc27ddadc16e1e75103f4cfbf56
Version: 45d76f492938cdc27ddadc16e1e75103f4cfbf56
Version: 45d76f492938cdc27ddadc16e1e75103f4cfbf56
Version: 45d76f492938cdc27ddadc16e1e75103f4cfbf56
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/amd/pds_core/dev.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "3231aff8ab26111c54e630b1a200fc43a729dd14",
              "status": "affected",
              "version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
              "versionType": "git"
            },
            {
              "lessThan": "10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2",
              "status": "affected",
              "version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
              "versionType": "git"
            },
            {
              "lessThan": "784dd2bdc622ed3cc6ef8e113aa1852e252de36f",
              "status": "affected",
              "version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
              "versionType": "git"
            },
            {
              "lessThan": "560d559324169fe0583d54c475b5329550a86f71",
              "status": "affected",
              "version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
              "versionType": "git"
            },
            {
              "lessThan": "0e46b6635b03d29807f810c3b415c4755a3f958d",
              "status": "affected",
              "version": "45d76f492938cdc27ddadc16e1e75103f4cfbf56",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/amd/pds_core/dev.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.4"
            },
            {
              "lessThan": "6.4",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.142",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.92",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.34",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.142",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.92",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.34",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.11",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "6.4",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix error handling in pdsc_devcmd_wait\n\nFix two cases where pdsc_devcmd_wait() returns stale success from\nthe completion register instead of an error:\n\n1. FW crash: If firmware stops running, the wait loop breaks early with\n   running=false. The condition \"if ((!done || timeout) \u0026\u0026 running)\" is\n   false, so error handling is bypassed and stale status is returned.\n   Check !running first and return -ENXIO.\n\n2. Timeout: If a command times out, err is set to -ETIMEDOUT but then\n   overwritten by pdsc_err_to_errno(status) which reads stale status.\n   Return -ETIMEDOUT immediately after cleaning up.\n\nBoth errors now propagate to pdsc_devcmd_locked() which queues\nhealth_work for recovery."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is in the AMD/Pensando pds_core host driver for a network DPU/NIC whose firmware processes remote traffic; a remote attacker can crash or hang firmware via crafted packets, which drives kernel recovery through pdsc_devcmd_locked() during pdsc_fw_up/pdsc_setup.\nAC:L - Once the device is reachable, an attacker can reliably induce the triggering conditions (firmware crash or devcmd timeout) by sending concurrent or malformed network traffic to stress the DPU firmware, without depending on uncontrollable timing or memory layout.\nPR:N - Exploitation does not require host credentials; an unauthenticated remote attacker who can send traffic to the Pensando DSC interface can cause firmware failure that reaches pdsc_devcmd_wait() during automatic driver recovery, independent of devlink or root-only management paths.\nUI:N - No victim interaction is required beyond normal network connectivity to the affected DPU-backed host; recovery is triggered automatically by firmware failure and the driver\u0027s health/recovery workqueue path.\nS:U - The flaw affects host kernel driver state and device recovery within the same security authority; it does not cross a VM, container, or IOMMU boundary to impact a separate security domain.\nC:N - The bug is a logic error returning stale MMIO completion status rather than a memory-safety flaw; it does not expose arbitrary kernel memory, only misinterprets bounded device register contents from prior commands.\nI:N - There is no kernel memory corruption or arbitrary write primitive; the worst case is proceeding with stale device-command completion data, which affects driver/device recovery state rather than modifying protected host data.\nA:H - Masking firmware crash or timeout as success prevents immediate health_work recovery, can leave the driver believing a failed INIT/reset succeeded, and can cause prolonged or repeated loss of DPU/network availability on internet-facing cloud servers until manual intervention or repeated recovery cycles."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:39:43.750Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/3231aff8ab26111c54e630b1a200fc43a729dd14"
        },
        {
          "url": "https://git.kernel.org/stable/c/10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2"
        },
        {
          "url": "https://git.kernel.org/stable/c/784dd2bdc622ed3cc6ef8e113aa1852e252de36f"
        },
        {
          "url": "https://git.kernel.org/stable/c/560d559324169fe0583d54c475b5329550a86f71"
        },
        {
          "url": "https://git.kernel.org/stable/c/0e46b6635b03d29807f810c3b415c4755a3f958d"
        }
      ],
      "title": "pds_core: fix error handling in pdsc_devcmd_wait",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-64148",
    "datePublished": "2026-07-19T15:40:38.816Z",
    "dateReserved": "2026-07-19T07:54:57.037Z",
    "dateUpdated": "2026-08-05T12:39:43.750Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…