In the Linux kernel, the following vulnerability has been resolved:
pds_core: Fix pdsc_check_pci_health function to use work thread
When the driver notices fw_status == 0xff it tries to perform a PCI reset on itself via pci_reset_function() in the context of the driver's health thread. However, pdsc_reset_prepare calls pdsc_stop_health_thread(), which attempts to stop/flush the health thread. This results in a deadlock because the stop/flush will never complete since the driver called pci_reset_function() from the health thread context. Fix by changing the pdsc_check_pci_health_function() to queue a newly introduced pdsc_pci_reset_thread() on the pdsc's work queue.
Unloading the driver in the fw_down/dead state uncovered another issue, which can be seen in the following trace:
WARNING: CPU: 51 PID: 6914 at kernel/workqueue.c:1450 __queue_work+0x358/0x440 [...] RIP: 0010:__queue_work+0x358/0x440 [...] Call Trace: <TASK> ? __warn+0x85/0x140 ? __queue_work+0x358/0x440 ? report_bug+0xfc/0x1e0 ? handle_bug+0x3f/0x70 ? exc_invalid_op+0x17/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? __queue_work+0x358/0x440 queue_work_on+0x28/0x30 pdsc_devcmd_locked+0x96/0xe0 [pds_core] pdsc_devcmd_reset+0x71/0xb0 [pds_core] pdsc_teardown+0x51/0xe0 [pds_core] pdsc_remove+0x106/0x200 [pds_core] pci_device_remove+0x37/0xc0 device_release_driver_internal+0xae/0x140 driver_detach+0x48/0x90 bus_remove_driver+0x6d/0xf0 pci_unregister_driver+0x2e/0xa0 pdsc_cleanup_module+0x10/0x780 [pds_core] __x64_sys_delete_module+0x142/0x2b0 ? syscall_trace_enter.isra.18+0x126/0x1a0 do_syscall_64+0x3b/0x90 entry_SYSCALL_64_after_hwframe+0x72/0xdc RIP: 0033:0x7fbd9d03a14b [...]
Fix this by preventing the devcmd reset if the FW is not running.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Oracle_linux | — | Upgrade kernel-uek | Nov 13, 2025 | May 20, 2024 |
| Ubuntu | — | Upgrade linux-image-awsUpgrade linux-image-6.8.0-1008-oracle-64kUpgrade linux-image-oracleUpgrade linux-image-gkeUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1010-azureUpgrade linux-image-nvidia-64kUpgrade linux-image-oem-24.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.8.0-38-lowlatencyUpgrade linux-image-6.8.0-1009-nvidiaUpgrade linux-image-kvmUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1007-intelUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-1007-raspiUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gcpUpgrade linux-image-6.8.0-1008-oemUpgrade linux-image-6.8.0-1009-nvidia-64kUpgrade linux-image-6.8.0-1008-oracleUpgrade linux-image-6.8.0-1008-ibmUpgrade linux-image-6.8.0-38-genericUpgrade linux-image-lowlatency-64kUpgrade linux-image-raspiUpgrade linux-image-azure-fdeUpgrade linux-image-ibmUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-38-lowlatency-64kUpgrade linux-image-6.8.0-1006-gkeUpgrade linux-image-6.8.0-1010-gcpUpgrade linux-image-6.8.0-1011-awsUpgrade linux-image-azureUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-genericUpgrade linux-image-6.8.0-38-generic-64kUpgrade linux-image-generic-64kUpgrade linux-image-generic-lpaeUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1010-azure-fdeUpgrade linux-image-intelUpgrade linux-image-lowlatencyUpgrade linux-image-oem-24.04a | Jul 12, 2024 | May 20, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub