CVE-2026-68319
CVE CVE-2026-68319EUVD EUVD-2026-55420Veröffentlicht 2026-08-10T12:02:54.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix deadlock between reset thread and remove pci_reset_function() acquires device_lock before performing the reset. pdsc_remove() is called by the PCI core with device_lock already held. If pdsc_pci_reset_thread() is running when pdsc_remove() is called, destroy_workqueue() will block waiting for the work to complete, while the work is blocked waiting for device_lock - deadlock. Use pci_try_reset_function() which uses pci_dev_trylock() internally. This acquires both the device lock and the PCI config access lock without blocking - if either lock is contended, it returns -EAGAIN immediately. This avoids the deadlock while also ensuring proper config space access serialization during the reset. The pci_dev_get/put calls are also removed as they were unnecessary - the driver-owned workqueue is destroyed in pdsc_remove(), guaranteeing the work completes before remove returns. The PCI core holds its reference to pci_dev throughout the entire unbind sequence.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux 81665adf25d28a00a986533f1d3a5df76b79cad9 <54f905821f26d385fba407a920b51f0a752c76dc; 81665adf25d28a00a986533f1d3a5df76b79cad9 <90d9f3ef28843e6c35149324b8eefb427a7435c2; patch: 6.12.101; patch: 7.2-rc5; patch: 6.18.42; 38407914d48273d7f8ab765b9243658afe1c3ab6; 81665adf25d28a00a986533f1d3a5df76b79cad9 <19ef775c91c6bf4bd2b60f6616f4e28b621cdd6a; patch: 7.1.6; 6.8.7 <6.9; 81665adf25d28a00a986533f1d3a5df76b79cad9 <ab0eec0ff0a421737a37f510ceab5c6ea59cd05a; patch: 0; 6.9
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.