Description
In the Linux kernel, the following vulnerability has been resolved:

net: mana: Cap MSI-X vectors to the device MSI-X table size

mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix
and the CPU count, but never from the device MSI-X table. On a 1792 vCPU
M-series VM that yields 1793 while the table has 1024 entries, and
mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the
end of the region mapped by msix_map_region():

BUG: unable to handle page fault for address: ff8e347f8b99800c
RIP: 0010:msix_prepare_msi_desc+0x7a/0x90
RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000
Call Trace:
<TASK>
__msi_domain_alloc_irqs+0x13a/0x440
msi_domain_alloc_irq_at+0x149/0x1b0
mana_gd_setup+0x351/0x890
mana_gd_probe+0x274/0x390
</TASK>

RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table.

msi_insert_desc() does range check the index, but only against the MSI
domain hwsize, which matches the table only for devices on an MSI parent
domain. With a global PCI/MSI domain hwsize is MSI_XA_DOMAIN_SIZE, so
nothing bounds the request.

Cap num_msix_usable with pci_msix_vec_count().
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Crash)
Action: Apply Update
AI Analysis

Impact

The Linux kernel’s mana driver calculates the maximum number of usable MSI‑X vectors incorrectly, permitting a device to request more vectors than the hardware table contains. The resulting out‑of‑bounds access in msix_prepare_msi_desc triggers a page fault and a kernel BUG, causing a system crash. The flaw is limited to kernel instability and does not provide a remote code‑execution path.

Affected Systems

The vulnerability exists in the Linux kernel’s mana driver on devices that support the driver. Based on the description, it is inferred that devices such as Azure‑type VMs may be affected. All kernel releases that include the buggy mana_gd_query_max_resources calculation are affected until the patch that caps vector usage with pci_msix_vec_count() is applied. Common distributions shipping a standard kernel prior to the commit are therefore vulnerable.

Risk and Exploitability

EPSS indicates a probability of exploitation below 1 %, and the vulnerability is not listed in CISA’s KEV catalog. The issue requires local kernel or VM‑level access to trigger the out‑of‑bounds access, and its impact is a denial of service rather than privilege escalation or data disclosure.

Generated by OpenCVE AI on September 20, 2026 at 04:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a release that incorporates the patch which caps MSI‑X vectors using pci_msix_vec_count().
  • If a kernel upgrade is not feasible, disable MSI‑X support for the affected mana device or limit the vector count it requests by disabling the mana driver in high‑CPU VM scenarios.
  • Confirm that the number of virtual CPUs assigned to a VM does not exceed the host’s MSI‑X table size; reduce vCPU allocation if necessary to avoid triggering the out‑of‑bounds condition.

Generated by OpenCVE AI on September 20, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-788

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: mana: Cap MSI-X vectors to the device MSI-X table size mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix and the CPU count, but never from the device MSI-X table. On a 1792 vCPU M-series VM that yields 1793 while the table has 1024 entries, and mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the end of the region mapped by msix_map_region(): BUG: unable to handle page fault for address: ff8e347f8b99800c RIP: 0010:msix_prepare_msi_desc+0x7a/0x90 RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000 Call Trace: <TASK> __msi_domain_alloc_irqs+0x13a/0x440 msi_domain_alloc_irq_at+0x149/0x1b0 mana_gd_setup+0x351/0x890 mana_gd_probe+0x274/0x390 </TASK> RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table. msi_insert_desc() does range check the index, but only against the MSI domain hwsize, which matches the table only for devices on an MSI parent domain. With a global PCI/MSI domain hwsize is MSI_XA_DOMAIN_SIZE, so nothing bounds the request. Cap num_msix_usable with pci_msix_vec_count().
Title net: mana: Cap MSI-X vectors to the device MSI-X table size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:59.532Z

Reserved: 2026-09-11T19:38:34.785Z

Link: CVE-2026-90082

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:57.573

Modified: 2026-09-17T17:16:57.573

Link: CVE-2026-90082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-788

    Access of Memory Location After End of Buffer