In the Linux kernel, the following vulnerability has been resolved:
idpf: fix error handling in the init_task on load
If the init_task fails during a driver load, we end up without vports and netdevs, effectively failing the entire process. In that state a subsequent reset will result in a crash as the service task attempts to access uninitialized resources. Following trace is from an error in the init_task where the CREATE_VPORT (op 501) is rejected by the FW:
[40922.763136] idpf 0000:83:00.0: Device HW Reset initiated [40924.449797] idpf 0000:83:00.0: Transaction failed (op 501) [40958.148190] idpf 0000:83:00.0: HW reset detected [40958.161202] BUG: kernel NULL pointer dereference, address: 00000000000000a8 ... [40958.168094] Workqueue: idpf-0000:83:00.0-vc_event idpf_vc_event_task [idpf] [40958.168865] RIP: 0010:idpf_vc_event_task+0x9b/0x350 [idpf] ... [40958.177932] Call Trace: [40958.178491] <TASK> [40958.179040] process_one_work+0x226/0x6d0 [40958.179609] worker_thread+0x19e/0x340 [40958.180158] ? __pfx_worker_thread+0x10/0x10 [40958.180702] kthread+0x10f/0x250 [40958.181238] ? __pfx_kthread+0x10/0x10 [40958.181774] ret_from_fork+0x251/0x2b0 [40958.182307] ? __pfx_kthread+0x10/0x10 [40958.182834] ret_from_fork_asm+0x1a/0x30 [40958.183370] </TASK>
Fix the error handling in the init_task to make sure the service and mailbox tasks are disabled if the error happens during load. These are started in idpf_vc_core_init(), which spawns the init_task and has no way of knowing if it failed. If the error happens on reset, following successful driver load, the tasks can still run, as that will allow the netdevs to attempt recovery through another reset. Stop the PTP callbacks either way as those will be restarted by the call to idpf_vc_core_init() during a successful reset.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 31, 2026 |
| Ubuntu | — | Upgrade linux-image-azure-fdeUpgrade linux-image-gcp-64kUpgrade linux-image-nvidia-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1030-oemUpgrade linux-image-nvidia-hwe-24.04Upgrade linux-image-6.17.0-1019-oracle-64kUpgrade linux-image-azure-6.17Upgrade linux-image-nvidia-64k-hwe-24.04Upgrade linux-image-realtime-6.17Upgrade linux-image-oracle-64kUpgrade linux-image-azureUpgrade linux-image-6.17.0-1021-gcp-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-oem-24.04cUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-nvidia-64k-6.17Upgrade linux-image-6.17.0-1021-gcpUpgrade linux-image-oem-24.04dUpgrade linux-image-azure-fde-6.17Upgrade linux-image-gcpUpgrade linux-image-6.17.0-1031-nvidia-64kUpgrade linux-image-oem-24.04bUpgrade linux-image-oem-24.04Upgrade linux-image-6.17.0-1018-realtimeUpgrade linux-image-6.17.0-1018-azure-fdeUpgrade linux-image-6.17.0-1021-azureUpgrade linux-image-oracle-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-6.17.0-1019-oracleUpgrade linux-image-6.17.0-1031-nvidiaUpgrade linux-image-gcp-6.17Upgrade linux-image-oracle | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub