Answer in brief
CVE-2026-98020 records a Unknown severity vulnerability in pds_core: fix cmd_regs access racing BAR unmap on reset. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e96094c1d11cce4deb5da3c0500d49041ab845b8 <2cc697565fd19b5ba2d100cdd4a20dd6d263abc2 || >=e96094c1d11cce4deb5da3c0500d49041ab845b8 <fa31bd14c5042c6315bb2182c963f03ca6e79ca4 || >=e96094c1d11cce4deb5da3c0500d49041ab845b8 <09f831bfe39de5b8026fefb3d106b5cc93272170 || >=e96094c1d11cce4deb5da3c0500d49041ab845b8 <7980325b2f71e3f65c1323c39792e2455da6fab6 || f6ec6ac9432941ec85a2221c91b1ecfc85680d89 || 692488941283d72362274620b9abd28109fc459f || >=6.6.16 <6.7 || >=6.7.4 <6.8 | 2cc697565fd19b5ba2d100cdd4a20dd6d263abc2, fa31bd14c5042c6315bb2182c963f03ca6e79ca4, 09f831bfe39de5b8026fefb3d106b5cc93272170, 7980325b2f71e3f65c1323c39792e2455da6fab6, 6.7, 6.8 |
| Linux/Linuxgeneric | 6.8 | Not reported |
Published upstream
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix cmd_regs access racing BAR unmap on reset pdsc_reset_prepare() and pdsc_reset_done()'s pdsc_map_bars() error path clear/iounmap cmd_regs without devcmd_lock, and pdsc_legacy_firmware_update()'s download loop derefs cmd_regs after dropping and retaking the lock without re-checking. An FLR concurrent with a devlink flash can unmap cmd_regs under an in-flight devcmd, causing a NULL deref or a write to unmapped MMIO. Take devcmd_lock across the BAR unmap/remap, and re-check cmd_regs in the download loop. Only the PF maps cmd_regs and runs devcmd, so skip the unmap on a VF, as pdsc_remove() and pdsc_reset_done() already do. A reset that completes entirely within the unlocked window is not a correctness problem for the image: the device clears its update session, so a resumed download is rejected, and it verifies the staged image before writing a flash slot, reporting PDS_RC_BAD_FW rather than activating it. pdsc_unmap_bars() also clears info_regs, intr_status and intr_ctrl. The interrupt and start/stop readers of those are quiesced before the unmap by pdsc_fw_down(), which frees the interrupts and tears down the queues. The debugfs readers are not, since those files outlive a reset; that is pre-existing and out of scope here.
Quoted source text, attributed separately from HOL analysis.