Impact
The Linux kernel’s mana driver calculates the maximum number of usable MSI‑X vectors incorrectly, permitting a device to request more vectors than the hardware table contains. The resulting out‑of‑bounds access in msix_prepare_msi_desc triggers a page fault and a kernel BUG, causing a system crash. The flaw is limited to kernel instability and does not provide a remote code‑execution path.
Affected Systems
The vulnerability exists in the Linux kernel’s mana driver on devices that support the driver. Based on the description, it is inferred that devices such as Azure‑type VMs may be affected. All kernel releases that include the buggy mana_gd_query_max_resources calculation are affected until the patch that caps vector usage with pci_msix_vec_count() is applied. Common distributions shipping a standard kernel prior to the commit are therefore vulnerable.
Risk and Exploitability
EPSS indicates a probability of exploitation below 1 %, and the vulnerability is not listed in CISA’s KEV catalog. The issue requires local kernel or VM‑level access to trigger the out‑of‑bounds access, and its impact is a denial of service rather than privilege escalation or data disclosure.
OpenCVE Enrichment