CVE-2026-80917
CVE CVE-2026-80917EUVD EUVD-2026-75092Published 2026-09-09T16:13:15.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems On 32-bit systems the config space is too large to ioremap in one go, so pci_ecam_create() maps each bus segment separately and relies on the ->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in cfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for every config access. The generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus and ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c do not. As a result, on a 32-bit host using "pci-host-cam-generic" the per-bus mapping is never set up and the first config read dereferences a NULL base, crashing during bus enumeration: Unable to handle kernel NULL pointer dereference at virtual address 00000800 Oops [#1] CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43 Hardware name: Digilent Nexys-Video-A7 RV32 (DT) epc : pci_generic_config_read+0x40/0xb0 ra : pci_generic_config_read+0x2c/0xb0 [<c038db9c>] pci_generic_config_read+0x40/0xb0 [<c038da04>] pci_bus_read_config_dword+0x50/0xb0 [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec [<c039245c>] pci_scan_single_device+0xa4/0x11c [<c0392570>] pci_scan_slot+0x9c/0x23c [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4 [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8 [<c0393e54>] pci_host_probe+0x20/0xc8 [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4 Fix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks. Since pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c, move the CAM ops definition there as pci_generic_cam_ops (mirroring pci_generic_ecam_ops) and export it for pci-host-generic.c to reference. [mani: removed timestamp from log]
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.18.47; 8fe55ef23387ce3c7488375b1fd539420d7654bb <008cb88edb41f3c7c8e0ed763ff9f26719830984; a037ebbe72a4f98495b193112e2b2000e5e09eb5; 5.14; 8fe55ef23387ce3c7488375b1fd539420d7654bb <74456843f18ba7f3045974d7e8b88ab993152b8c; 8fe55ef23387ce3c7488375b1fd539420d7654bb <0c55707bd5d0d7670704cfd0dda933809b052f67; 5.13.4 <5.14; 8fe55ef23387ce3c7488375b1fd539420d7654bb <8d08713ec83a18526d1ed1fd5f0d2b901d103a10; patch: 6.1.185; 8fe55ef23387ce3c7488375b1fd539420d7654bb <5e52eb0290f66ba0732956dcb1e365b5ca3c5108; 8fe55ef23387ce3c7488375b1fd539420d7654bb <a199293f3038db8d31d47aa60f1e18272cd82354; patch: 6.12.106; patch: 6.6.154; 0b5877a1aeacdbf32b3bea91326592004ec7806f; patch: 5.15.218; 8fe55ef23387ce3c7488375b1fd539420d7654bb <0916948026f623844acd08888f7cbedbf1c48d6b; patch: 7.2.1; patch: 0; 5.12.19 <5.13; patch: 7.3-rc1; 8fe55ef23387ce3c7488375b1fd539420d7654bb <baf9b0383ff770fdff123d3a832f3a99641d96dd; patch: 7.1.11
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.