CVE-2026-68317

Unknown

Last modified

CVE-2026-68317 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: pds_core: fix auxiliary device add/del races Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler. They serialize on config_lock, but neither guards the slot under it correctly. add() registers and stores a new auxiliary device without first checking the slot, so a second add of an already-populated slot leaks the first device. del() makes that check outside config_lock, so two concurrent dels can both pass it; the first clears the slot, and the second dereferences a NULL pointer. Check and update the slot under config_lock in both paths..

Description

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix auxiliary device add/del races Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler. They serialize on config_lock, but neither guards the slot under it correctly. add() registers and stores a new auxiliary device without first checking the slot, so a second add of an already-populated slot leaks the first device. del() makes that check outside config_lock, so two concurrent dels can both pass it; the first clears the slot, and the second dereferences a NULL pointer. Check and update the slot under config_lock in both paths.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 0861fccd43b8bafb533d97308862d20b7db3a2ad, < 646b58b543f3bb1641e9123b75ff7799fe7b42f1; >= f41e27b746241e57d968d1d61c008322338ca258, < ef194751fed50cf3452017b63f00142a0ab40c70; >= b699bdc720c0255d1bb76cecba7382c1f2107af5, < cf0ed2ba202f5c3b300ec1bf7ff0b5d555f7d518; >= b699bdc720c0255d1bb76cecba7382c1f2107af5, < bdeab32a7a91acd295d52a2d4ab1cc3f2da5e454; >= b699bdc720c0255d1bb76cecba7382c1f2107af5, < bfa33cd513c7ceb93c5a4c30e5662acd73c0a916; fec5f7af1d5f64a38f9224cd27b274d1af55a7ed; >= 6.6.90, < 6.6.148; >= 6.12.28, < 6.12.101; >= 6.14.6, < 6.15
LinuxLinux6.15

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68317?
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix auxiliary device add/del races Two paths add or delete the same slot (pf->vfs[vf_id].padev): a VF's pdsc_reset_done() and the PF's devlink enable_vnet/disable_vnet handler. They serialize on config_lock, but neither guards the slot under it correctly. add() registers and stores a new auxiliary device without first checking the slot, so a second add of an already-populated slot leaks the first device. del() makes that check outside config_lock, so two concurrent dels can both pass it; the first clears the slot, and the second dereferences a NULL pointer. Check and update the slot under config_lock in both paths.
How severe is CVE-2026-68317?
Severity scoring for CVE-2026-68317 is pending analysis.
How do I fix CVE-2026-68317?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68317?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST