CVE-2026-23361: PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
In the Linux kernel, the following vulnerability has been resolved:
PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
Endpoint drivers use dwpcieepraisemsixirq() to raise an MSI-X interrupt to the host using a writel(), which generates a PCI posted write transaction. There's no completion for posted writes, so the writel() may return before the PCI write completes. dwpcieepraisemsixirq() also unmaps the outbound ATU entry used for the PCI write, so the write races with the unmap.
If the PCI write loses the race with the ATU unmap, the write may corrupt host memory or cause IOMMU errors, e.g., these when running fio with a larger queue depth against nvmet-pci-epf:
arm-smmu-v3 fc900000.iommu: 0x0000010000000010 arm-smmu-v3 fc900000.iommu: 0x0000020000000000 arm-smmu-v3 fc900000.iommu: 0x000000090000f040 arm-smmu-v3 fc900000.iommu: 0x0000000000000000 arm-smmu-v3 fc900000.iommu: event: FTRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0 arm-smmu-v3 fc900000.iommu: unpriv data write s1 "Input address caused fault" stag: 0x0
Flush the write by performing a readl() of the same address to ensure that the write has reached the destination before the ATU entry is unmapped.
The same problem was solved for dwpcieepraisemsiirq() in commit 8719c64e76bf ("PCI: dwc: ep: Cache MSI outbound iATU mapping"), but there it was solved by dedicating an outbound iATU only for MSI. We can't do the same for MSI-X because each vector can have a different msgaddr and the msgaddr may be changed while the vector is masked.
[bhelgaas: commit log]
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In dw_pcie_ep_raise_msix_irq(), flush the PCI posted MSI-X write by performing a readl() from the same address before unmapping the outbound ATU entry, ensuring the write reaches its destination before the mapping is removed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23361?
CVE-2026-23361 is classified as a vulnerability that affects the integrity of PCI endpoint drivers in the Linux kernel.
How do I fix CVE-2026-23361?
To fix CVE-2026-23361, you must update your Linux kernel to a patched version released by the Linux community.
Which versions of the Linux kernel are affected by CVE-2026-23361?
CVE-2026-23361 affects Linux kernel versions between 4.19.1 and 6.19.7 and certain 7.0 release candidates.
What impact does CVE-2026-23361 have on system security?
CVE-2026-23361 can potentially allow unauthorized access to system resources through improper handling of MSI-X interrupts.
Is CVE-2026-23361 a locally exploitable vulnerability?
Yes, CVE-2026-23361 can be exploited locally by an attacker with access to the affected PCI endpoint drivers.