CVE-2026-23361: PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry

Published Mar 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry

Endpoint drivers use dwpcieepraisemsixirq() to raise an MSI-X interrupt to the host using a writel(), which generates a PCI posted write transaction. There's no completion for posted writes, so the writel() may return before the PCI write completes. dwpcieepraisemsixirq() also unmaps the outbound ATU entry used for the PCI write, so the write races with the unmap.

If the PCI write loses the race with the ATU unmap, the write may corrupt host memory or cause IOMMU errors, e.g., these when running fio with a larger queue depth against nvmet-pci-epf:

arm-smmu-v3 fc900000.iommu: 0x0000010000000010 arm-smmu-v3 fc900000.iommu: 0x0000020000000000 arm-smmu-v3 fc900000.iommu: 0x000000090000f040 arm-smmu-v3 fc900000.iommu: 0x0000000000000000 arm-smmu-v3 fc900000.iommu: event: FTRANSLATION client: 0000:01:00.0 sid: 0x100 ssid: 0x0 iova: 0x90000f040 ipa: 0x0 arm-smmu-v3 fc900000.iommu: unpriv data write s1 "Input address caused fault" stag: 0x0

Flush the write by performing a readl() of the same address to ensure that the write has reached the destination before the ATU entry is unmapped.

The same problem was solved for dwpcieepraisemsiirq() in commit 8719c64e76bf ("PCI: dwc: ep: Cache MSI outbound iATU mapping"), but there it was solved by dedicating an outbound iATU only for MSI. We can't do the same for MSI-X because each vector can have a different msgaddr and the msgaddr may be changed while the vector is masked.

[bhelgaas: commit log]

Affected Software

12 affected components
Linux Linux kernel (dwc PCIe endpoint driver)
Linux Linux kernel>=4.19.1<6.12.77
Linux Linux kernel>=6.13<6.18.17
Linux Linux kernel>=6.19<6.19.7
Linux Linux kernel=4.19
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    In dw_pcie_ep_raise_msix_irq(), flush the PCI posted MSI-X write by performing a readl() from the same address before unmapping the outbound ATU entry, ensuring the write reaches its destination before the mapping is removed.

Event History

Mar 25, 2026
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 26, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-23361?

CVE-2026-23361 is classified as a vulnerability that affects the integrity of PCI endpoint drivers in the Linux kernel.

2

How do I fix CVE-2026-23361?

To fix CVE-2026-23361, you must update your Linux kernel to a patched version released by the Linux community.

3

Which versions of the Linux kernel are affected by CVE-2026-23361?

CVE-2026-23361 affects Linux kernel versions between 4.19.1 and 6.19.7 and certain 7.0 release candidates.

4

What impact does CVE-2026-23361 have on system security?

CVE-2026-23361 can potentially allow unauthorized access to system resources through improper handling of MSI-X interrupts.

5

Is CVE-2026-23361 a locally exploitable vulnerability?

Yes, CVE-2026-23361 can be exploited locally by an attacker with access to the affected PCI endpoint drivers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203