← All Advisories

CVE-2026-98020

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98020

Key Details

CVECVE-2026-98020
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

pds_core: fix cmd_regs access racing BAR unmap on reset

pdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path

clear/iounmap cmd_regs without devcmd_lock, and

pdsc_legacy_firmware_update()'s download loop derefs cmd_regs after

dropping and retaking the lock without re-checking. An FLR concurrent

with a devlink flash can unmap cmd_regs under an in-flight devcmd,

causing a NULL deref or a write to unmapped MMIO.

Take devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in

the download loop. Only the PF maps cmd_regs and runs devcmd, so skip

the unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do.

A reset that completes entirely within the unlocked window is not a

correctness problem for the image: the device clears its update session,

so a resumed download is rejected, and it verifies the staged image

before writing a flash slot, reporting PDS_RC_BAD_FW rather than

activating it.

pdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The

interrupt and start/stop readers of those are quiesced before the unmap

by pdsc_fw_down(), which frees the interrupts and tears down the queues.

The debugfs readers are not, since those files outlive a reset; that is

pre-existing and out of scope here. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98020
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98020