In the Linux kernel, the following vulnerability has been resolved:
PCI: Hold rescan lock while adding devices during host probe
Since adding the PCI power control code, we may end up with a race between the pwrctl platform device rescanning the bus and host controller probe functions. The latter need to take the rescan lock when adding devices or we may end up in an undefined state having two incompletely added devices and hit the following crash when trying to remove the device over sysfs:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 Internal error: Oops: 0000000096000004 [#1] SMP Call trace: __pi_strlen+0x14/0x150 kernfs_find_ns+0x80/0x13c kernfs_remove_by_name_ns+0x54/0xf0 sysfs_remove_bin_file+0x24/0x34 pci_remove_resource_files+0x3c/0x84 pci_remove_sysfs_dev_files+0x28/0x38 pci_stop_bus_device+0x8c/0xd8 pci_stop_bus_device+0x40/0xd8 pci_stop_and_remove_bus_device_locked+0x28/0x48 remove_store+0x70/0xb0 dev_attr_store+0x20/0x38 sysfs_kf_write+0x58/0x78 kernfs_fop_write_iter+0xe8/0x184 vfs_write+0x2dc/0x308 ksys_write+0x7c/0xec
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 5, 2024 |
| Ubuntu | — | Upgrade linux-image-oem-24.04Upgrade linux-image-oracle-64kUpgrade linux-image-awsUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.11.0-1010-lowlatencyUpgrade linux-image-6.11.0-1009-awsUpgrade linux-image-oem-24.04aUpgrade linux-image-azureUpgrade linux-image-realtimeUpgrade linux-image-raspiUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-6.11.0-18-genericUpgrade linux-image-gcpUpgrade linux-image-6.11.0-1008-raspiUpgrade linux-image-6.11.0-1015-oemUpgrade linux-image-6.11.0-1010-lowlatency-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-virtualUpgrade linux-image-6.11.0-1009-azureUpgrade linux-image-lowlatency-64kUpgrade linux-image-azure-fdeUpgrade linux-image-6.11.0-1009-gcpUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-genericUpgrade linux-image-6.11.0-1011-oracleUpgrade linux-image-oracleUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.11.0-1011-oracle-64kUpgrade linux-image-6.11.0-1005-realtimeUpgrade linux-image-lowlatencyUpgrade linux-image-6.11.0-1009-azure-fdeUpgrade linux-image-6.11.0-18-generic-64kUpgrade linux-image-generic-64k | Feb 20, 2025 | Nov 5, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub