Description
In the Linux kernel, the following vulnerability has been resolved:

PCI: Allow per function PCI slots to fix slot reset on s390

On s390 systems, which use a machine level hypervisor, PCI devices are
always accessed through a form of PCI pass-through which fundamentally
operates on a per PCI function granularity. This is also reflected in the
s390 PCI hotplug driver which creates hotplug slots for individual PCI
functions. Its reset_slot() function, which is a wrapper for
zpci_hot_reset_device(), thus also resets individual functions.

Currently, the pci_create_slot() assigns the same pci_slot object to
multifunction devices. This approach worked fine on s390 systems that only
exposed virtual functions as individual PCI domains to the operating
system. Since commit 44510d6fa0c0 ("s390/pci: Handling multifunctions")
s390 supports exposing the topology of multifunction PCI devices by
grouping them in a shared PCI domain. This creates a problem when resetting
a function through the hotplug driver's slot_reset() interface.

When attempting to reset a function through the hotplug driver, the shared
slot assignment causes the wrong function to be reset instead of the
intended one. It also leaks memory as we do create a pci_slot object for
the function, but don't correctly free it in pci_slot_release().

Add a flag for struct pci_slot to allow per function PCI slots for
functions managed through a hypervisor, which exposes individual PCI
functions while retaining the topology. Since we can use all 8 bits for
slot 'number' (for ARI devices), change slot 'number' u16 to account for
special values PCI_SLOT_PLACEHOLDER and PCI_SLOT_ALL_DEVICES.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Device reset failure and memory leak that can lead to PCI device malfunction and system instability
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel on s390 machines can reset the wrong PCI function when handling multifunction devices, because the hotplug driver assigns the same pci_slot object to all functions. This logic flaw also causes a memory leak due to unreleased pci_slot objects. The vulnerability therefore results in faulty PCI resets and can degrade system stability or interrupt critical services. The associated CVSS score of 8.4 indicates a high impact, but the EPSS score of less than 1% shows that exploitation is currently considered unlikely. The vulnerability is not listed in CISA’s KEV catalog.

Affected Systems

The flaw affects the Linux kernel on s390 hardware. No specific kernel release or version is identified in the advisory, so all s390 deployments running a kernel that supports PCI hotplug are potentially susceptible. The advisory references the core kernel Git repository in which the patch is applied.

Risk and Exploitability

The attack vector likely requires privileged local access or kernel-level compromise to trigger the wrong reset of a PCI device. Exploitation would involve invoking the hotplug driver’s reset_slot() interface on a target function, which could result in an incorrect hardware reset and memory leak. Because the weakness is internal to the driver logic, remote exploitation is improbable without additional local privileges. The low EPSS score reflects this limited exposure. Nonetheless, the high CVSS score suggests that once exploited, the effect on availability or integrity could be serious.

Generated by OpenCVE AI on September 18, 2026 at 10:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the fix for per-function PCI slots on s390, such as the change introduced by commit 2050d900f9adbd6d6f38d30e182bcd9ad3108467 or newer releases that incorporate it.
  • If an updated kernel is not yet available, consider disabling PCI hotplug functionality for multifunction devices on the s390 system to avoid the possibility of a wrong reset.
  • Deploy monitoring of kernel logs (e.g., dmesg) for any PCI reset related warning or error messages so that a potential issue can be detected early.
  • Stay current with subsequent kernel releases that address similar PCI driver weaknesses, ensuring ongoing protection against related bugs.

Generated by OpenCVE AI on September 18, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 11:15:00 +0000


Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459
CWE-703

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, which use a machine level hypervisor, PCI devices are always accessed through a form of PCI pass-through which fundamentally operates on a per PCI function granularity. This is also reflected in the s390 PCI hotplug driver which creates hotplug slots for individual PCI functions. Its reset_slot() function, which is a wrapper for zpci_hot_reset_device(), thus also resets individual functions. Currently, the pci_create_slot() assigns the same pci_slot object to multifunction devices. This approach worked fine on s390 systems that only exposed virtual functions as individual PCI domains to the operating system. Since commit 44510d6fa0c0 ("s390/pci: Handling multifunctions") s390 supports exposing the topology of multifunction PCI devices by grouping them in a shared PCI domain. This creates a problem when resetting a function through the hotplug driver's slot_reset() interface. When attempting to reset a function through the hotplug driver, the shared slot assignment causes the wrong function to be reset instead of the intended one. It also leaks memory as we do create a pci_slot object for the function, but don't correctly free it in pci_slot_release(). Add a flag for struct pci_slot to allow per function PCI slots for functions managed through a hypervisor, which exposes individual PCI functions while retaining the topology. Since we can use all 8 bits for slot 'number' (for ARI devices), change slot 'number' u16 to account for special values PCI_SLOT_PLACEHOLDER and PCI_SLOT_ALL_DEVICES.
Title PCI: Allow per function PCI slots to fix slot reset on s390
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-10-03T10:56:39.032Z

Reserved: 2026-09-11T19:38:34.767Z

Link: CVE-2026-89795

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:44.307

Modified: 2026-10-03T11:17:43.450

Link: CVE-2026-89795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:00:09Z

Weaknesses
  • CWE-459

    Incomplete Cleanup

  • CWE-703

    Improper Check or Handling of Exceptional Conditions