pds_core: fix error handling in pdsc_devcmd_wait
Summary
| CVE | CVE-2026-64148 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:56 UTC |
| Updated | 2026-07-19 16:17:56 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
pds_core: fix error handling in pdsc_devcmd_wait
Fix two cases where pdsc_devcmd_wait() returns stale success from
the completion register instead of an error:
1. FW crash: If firmware stops running, the wait loop breaks early with
running=false. The condition "if ((!done || timeout) && running)" is
false, so error handling is bypassed and stale status is returned.
Check !running first and return -ENXIO.
2. Timeout: If a command times out, err is set to -ETIMEDOUT but then
overwritten by pdsc_err_to_errno(status) which reads stale status.
Return -ETIMEDOUT immediately after cleaning up.
Both errors now propagate to pdsc_devcmd_locked() which queues
health_work for recovery. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 45d76f492938cdc27ddadc16e1e75103f4cfbf56 3231aff8ab26111c54e630b1a200fc43a729dd14 git |
Not specified |
| CNA |
Linux |
Linux |
affected 45d76f492938cdc27ddadc16e1e75103f4cfbf56 10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 45d76f492938cdc27ddadc16e1e75103f4cfbf56 784dd2bdc622ed3cc6ef8e113aa1852e252de36f git |
Not specified |
| CNA |
Linux |
Linux |
affected 45d76f492938cdc27ddadc16e1e75103f4cfbf56 560d559324169fe0583d54c475b5329550a86f71 git |
Not specified |
| CNA |
Linux |
Linux |
affected 45d76f492938cdc27ddadc16e1e75103f4cfbf56 0e46b6635b03d29807f810c3b415c4755a3f958d git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.4 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.4 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/784dd2bdc622ed3cc6ef8e113aa1852e252de36f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/3231aff8ab26111c54e630b1a200fc43a729dd14 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/0e46b6635b03d29807f810c3b415c4755a3f958d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/560d559324169fe0583d54c475b5329550a86f71 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.