s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump
In the Linux kernel, the following vulnerability has been resolved: s390/pci: Avoid deadlock between PCI error recovery and mlx5 crdump Do not block PCI config accesses through pci_cfg_access_lock() when executing the s390 variant of PCI error recovery: Acquire just device_lock() instead of pci_dev_lock() as powerpc's EEH and generig PCI AER processing do. During error recovery testing a pair of tasks was reported to be hung: mlx5_core 0000:00:00.1: mlx5_health_try_recover:338:(pid 5553): health recovery flow aborted, PCI reads still not working INFO: task kmcheck:72 blocked for more than 122 seconds. Not tainted 5.14.0-570.12.1.bringup7.el9.s390x #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kmcheck state:D stack:0 pid:72 tgid:72 ppid:2 flags:0x00000000 Call Trace: [<000000065256f030>] __schedule+0x2a0/0x590 [<000000065256f356>] schedule+0x36/0xe0 [<000000065256f572>] schedule_preempt_disabled+0x22/0x30 [<0000000652570a94>] __mutex_lock.constprop.0+0x484/0x8a8 [<000003ff800673a4>] mlx5_unload_one+0x34/0x58 [mlx5_core] [<000003ff8006745c>] mlx5_pci_err_detected+0x94/0x140 [mlx5_core] [<0000000652556c5a>] zpci_event_attempt_error_recovery+0xf2/0x398 [<0000000651b9184a>] __zpci_event_error+0x23a/0x2c0 INFO: task kworker/u1664:6:1514 blocked for more than 122 seconds. Not tainted 5.14.0-570.12.1.bringup7.el9.s390x #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. task:kworker/u1664:6 state:D stack:0 pid:1514 tgid:1514 ppid:2 flags:0x00000000 Workqueue: mlx5_health0000:00:00.0 mlx5_fw_fatal_reporter_err_work [mlx5_core] Call Trace: [<000000065256f030>] __schedule+0x2a0/0x590 [<000000065256f356>] schedule+0x36/0xe0 [<0000000652172e28>] pci_wait_cfg+0x80/0xe8 [<0000000652172f94>] pci_cfg_access_lock+0x74/0x88 [<000003ff800916b6>] mlx5_vsc_gw_lock+0x36/0x178 [mlx5_core] [<000003ff80098824>] mlx5_crdump_collect+0x34/0x1c8 [mlx5_core] [<000003ff80074b62>] mlx5_fw_fatal_reporter_dump+0x6a/0xe8 [mlx5_core] [<0000000652512242>] devlink_health_do_dump.part.0+0x82/0x168 [<0000000652513212>] devlink_health_report+0x19a/0x230 [<000003ff80075a12>] mlx5_fw_fatal_reporter_err_work+0xba/0x1b0 [mlx5_core] No kernel log of the exact same error with an upstream kernel is available - but the very same deadlock situation can be constructed there, too: - task: kmcheck mlx5_unload_one() tries to acquire devlink lock while the PCI error recovery code has set pdev->block_cfg_access by way of pci_cfg_access_lock() - task: kworker mlx5_crdump_collect() tries to set block_cfg_access through pci_cfg_access_lock() while devlink_health_report() had acquired the devlink lock. A similar deadlock situation can be reproduced by requesting a crdump with > devlink health dump show pci/<BDF> reporter fw_fatal while PCI error recovery is executed on the same <BDF> physical function by mlx5_core's pci_error_handlers. On s390 this can be injected with > zpcictl --reset-fw <BDF> Tests with this patch failed to reproduce that second deadlock situation, the devlink command is rejected with "kernel answers: Permission denied" - and we get a kernel log message of: mlx5_core 1ed0:00:00.1: mlx5_crdump_collect:50:(pid 254382): crdump: failed to lock vsc gw err -5 because the config read of VSC_SEMAPHORE is rejected by the underlying hardware. Two prior attempts to address this issue have been discussed and ultimately rejected [see link], with the primary argument that s390's implementation of PCI error recovery is imposing restrictions that neither powerpc's EEH nor PCI AER handling need. Tests show that PCI error recovery on s390 is running to completion even without blocking access to PCI config space.
- Yayın
- 16 Ara 2025
- Güncelleme
- 17 Haz 2026
- EPSS
- %0,2 · 8. yüzdelik
- CWE
- —
Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.
Rapor araçları
Aksiyon skoru
0
İzleyin
Şimdilik düşük öncelik.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Listede değil
- EPSS
- 0 / 30 · %0,2
Noroxi analizi
Bu kayıt için henüz Noroxi analizi yok
Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.
Bu ürünü kullanıyoruz, yardım isteyinEtkilenen sistemler
—
Üreticinin bildirdiği sürümler
Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.
Linux Linux
- 5.16etkilenir
- 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e ve sonrası · d0df2503bc3c2be385ca2fd96585daad1870c7c5 öncesietkilenir · git
- 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e ve sonrası · b63c061be622b17b495cbf78a6d5f2d4c3147f8e öncesietkilenir · git
- 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e ve sonrası · 3591d56ea9bfd3e7fbbe70f749bdeed689d415f9 öncesietkilenir · git
- 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e ve sonrası · 54f938d9f5693af8ed586a08db4af5d9da1f0f2d öncesietkilenir · git
- 4cdf2f4e24ff0d345fc36ef6d6aec059333a261e ve sonrası · 0fd20f65df6aa430454a0deed8f43efa91c54835 öncesietkilenir · git
- 5.16 öncesietkilenmez · semver
- 6.1.159 ve sonrası · 6.1.* dahil öncesietkilenmez · semver
- 6.6.117 ve sonrası · 6.6.* dahil öncesietkilenmez · semver
- 6.12.58 ve sonrası · 6.12.* dahil öncesietkilenmez · semver
Paket düzeyi etkilenme
OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.
| Ekosistem | Paket | Etkilenen aralık | Düzeltme |
|---|---|---|---|
| Debian:12 | linux | 6.1.159-1 öncesi | 6.1.159-1 |
| Debian:13 | linux | 6.12.63-1 öncesi | 6.12.63-1 |
| Debian:14 | linux | 6.17.8-1 öncesi | 6.17.8-1 |
| SUSE:Linux Enterprise Live Patching 15 SP7 | kernel-livepatch-SLE15-SP7_Update_15 | 1-150700.15.3.1 öncesi | 1-150700.15.3.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP7 | kernel-64kb | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP7 | kernel-default | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP7 | kernel-default-base | 6.4.0-150700.53.55.1.150700.17.33.1 öncesi | 6.4.0-150700.53.55.1.150700.17.33.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP7 | kernel-source | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Basesystem 15 SP7 | kernel-zfcpdump | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP7 | kernel-docs | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP7 | kernel-obs-build | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Development Tools 15 SP7 | kernel-syms | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Enterprise Module for Public Cloud 15 SP7 | kernel-azure | 6.4.0-150700.53.55.1 öncesi | 6.4.0-150700.53.55.1 |
| SUSE:Linux Micro Extras 6.2 | kernel-obs-build | 6.12.0-160000.33.1 öncesi | 6.12.0-160000.33.1 |
| SUSE:Linux Micro Extras 6.2 | kernel-syms | 6.12.0-160000.33.1 öncesi | 6.12.0-160000.33.1 |
Aynı üründe
linux: tüm kayıtlarAynı birincil ürünün en yüksek skorlu diğer kayıtları.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Planlayın
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Planlayın
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Planlayın
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Planlayın
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Planlayın
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Planlayın
Düzeltme
Hangi sürüme geçmeli
Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.
| Ürün / paket | Düzeltilmiş sürüm | Kaynak |
|---|---|---|
| Linux Linux | 0fd20f65df6aa430454a0deed8f43efa91c54835 | Üretici (CNA) |
| Linux Linux | 3591d56ea9bfd3e7fbbe70f749bdeed689d415f9 | Üretici (CNA) |
| Linux Linux | 54f938d9f5693af8ed586a08db4af5d9da1f0f2d | Üretici (CNA) |
| Linux Linux | b63c061be622b17b495cbf78a6d5f2d4c3147f8e | Üretici (CNA) |
| Linux Linux | d0df2503bc3c2be385ca2fd96585daad1870c7c5 | Üretici (CNA) |
| debian:linux | 6.1.159-1 · Debian:12 | Paket deposu (OSV) |
| suse:kernel-64kb | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP7 | Paket deposu (OSV) |
| suse:kernel-azure | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Public Cloud 15 SP7 | Paket deposu (OSV) |
| suse:kernel-default | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP7 | Paket deposu (OSV) |
| suse:kernel-default-base | 6.4.0-150700.53.55.1.150700.17.33.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP7 | Paket deposu (OSV) |
| suse:kernel-docs | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Development Tools 15 SP7 | Paket deposu (OSV) |
| suse:kernel-livepatch-SLE15-SP7_Update_15 | 1-150700.15.3.1 · SUSE:Linux Enterprise Live Patching 15 SP7 | Paket deposu (OSV) |
| suse:kernel-obs-build | 6.12.0-160000.33.1 · SUSE:Linux Micro Extras 6.2 | Paket deposu (OSV) |
| suse:kernel-source | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP7 | Paket deposu (OSV) |
| suse:kernel-syms | 6.12.0-160000.33.1 · SUSE:Linux Micro Extras 6.2 | Paket deposu (OSV) |
| suse:kernel-zfcpdump | 6.4.0-150700.53.55.1 · SUSE:Linux Enterprise Module for Basesystem 15 SP7 | Paket deposu (OSV) |
İstismar durumu
Bilinen kamuya açık istismar yok
Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.
Araştırma bağlamı
Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.
Zaman çizelgesi
Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.
Yayın dışında tarihli olay yok.
FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).
Yama ve commit bağlantıları
Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.
Referanslarda commit ya da PR bağlantısı yok.
Kredi
Tüm araştırmacılarCNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.
CNA kaydında kredi yok.
Varyant adayları
Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.
Gece hesaplanan ilişki yok.
Zincir adayları
Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.
—
Bug bounty kapsamı
Bilinen herkese açık program yok.
Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).
Teknik detay
Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.
Zayıflık sınıfı (CWE)
—
Saldırı bağlamı
Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.
Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.
Değişiklik günlüğü
- Düzeltme✗ → ✓
Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →
Referanslar
- git.kernel.org/stable/c/0fd20f65df6aa430454a0deed8f43efa91c54835
- git.kernel.org/stable/c/3591d56ea9bfd3e7fbbe70f749bdeed689d415f9
- git.kernel.org/stable/c/54f938d9f5693af8ed586a08db4af5d9da1f0f2d
- git.kernel.org/stable/c/b63c061be622b17b495cbf78a6d5f2d4c3147f8e
- git.kernel.org/stable/c/d0df2503bc3c2be385ca2fd96585daad1870c7c5
Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.