CVE-2026-64430: NTB: epf: Avoid calling pci_irq_vector() from hardirq context

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:50:47 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072536-CVE-2026-64430-3346@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

NTB: epf: Avoid calling pci_irq_vector() from hardirq context

ntb_epf_vec_isr() calls pci_irq_vector() in hardirq context to derive
the vector number. pci_irq_vector() calls msi_get_virq() that takes a
mutex and can therefore trigger "scheduling while atomic" splats:

  BUG: scheduling while atomic: kworker/u33:0/55/0x00010001
  ...
  Call trace:
   ...
   schedule+0x38/0x110
   schedule_preempt_disabled+0x28/0x50
   __mutex_lock.constprop.0+0x848/0x908
   __mutex_lock_slowpath+0x18/0x30
   mutex_lock+0x4c/0x60
   msi_domain_get_virq+0xe8/0x138
   pci_irq_vector+0x2c/0x60
   ntb_epf_vec_isr+0x28/0x120 [ntb_hw_epf]
   __handle_irq_event_percpu+0x70/0x3a8
   handle_irq_event+0x48/0x100
   handle_edge_irq+0x100/0x1c8
   ...

Cache the Linux IRQ number for vector 0 when vectors are allocated and
use it as a base in the ISR. Running the ISR in a threaded IRQ handler
would also avoid the problem, but that would be unnecessary here.

The Linux kernel CVE team has assigned CVE-2026-64430 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 5.15.212 with commit 33bba331a4a5fee8b6026fe72eca13cceeec1b7b
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 6.1.178 with commit aff271b12a1eb8c8b3da19223ae1a6abe1e8168b
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 6.6.145 with commit 1dba8444ac0100133d72374634f6d7451fff1ccc
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 6.12.96 with commit 174a97f21bf9c54fa37ec0f321692e862ea130a3
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 6.18.39 with commit f71e8d9875069fa73e335f63f02ec6e52e3aaa51
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 7.1.4 with commit 6350df503897d57c5634f71b0767d48c3b837583
	Issue introduced in 5.12 with commit 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb and fixed in 7.2-rc1 with commit 4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64430
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/ntb/hw/epf/ntb_hw_epf.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/33bba331a4a5fee8b6026fe72eca13cceeec1b7b
	https://git.kernel.org/stable/c/aff271b12a1eb8c8b3da19223ae1a6abe1e8168b
	https://git.kernel.org/stable/c/1dba8444ac0100133d72374634f6d7451fff1ccc
	https://git.kernel.org/stable/c/174a97f21bf9c54fa37ec0f321692e862ea130a3
	https://git.kernel.org/stable/c/f71e8d9875069fa73e335f63f02ec6e52e3aaa51
	https://git.kernel.org/stable/c/6350df503897d57c5634f71b0767d48c3b837583
	https://git.kernel.org/stable/c/4dcddc1c794d1c65eda68f1f8dd04a0fecc0870f