{"api_version":"1","generated_at":"2026-09-10T22:31:56+00:00","cve":"CVE-2026-80917","urls":{"html":"https://cve.report/CVE-2026-80917","api":"https://cve.report/api/cve/CVE-2026-80917.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80917","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80917"},"summary":{"title":"PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus\nand ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n  ra : pci_generic_config_read+0x2c/0xb0\n [<c038db9c>] pci_generic_config_read+0x40/0xb0\n [<c038da04>] pci_bus_read_config_dword+0x50/0xb0\n [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [<c039245c>] pci_scan_single_device+0xa4/0x11c\n [<c0392570>] pci_scan_slot+0x9c/0x23c\n [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4\n [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8\n [<c0393e54>] pci_host_probe+0x20/0xc8\n [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-09 17:17:46","updated_at":"2026-09-09 17:17:46"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10","name":"https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108","name":"https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67","name":"https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354","name":"https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd","name":"https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b","name":"https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984","name":"https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c","name":"https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80917","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80917","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 5e52eb0290f66ba0732956dcb1e365b5ca3c5108 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb baf9b0383ff770fdff123d3a832f3a99641d96dd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 8d08713ec83a18526d1ed1fd5f0d2b901d103a10 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 74456843f18ba7f3045974d7e8b88ab993152b8c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 0c55707bd5d0d7670704cfd0dda933809b052f67 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb a199293f3038db8d31d47aa60f1e18272cd82354 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 0916948026f623844acd08888f7cbedbf1c48d6b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 8fe55ef23387ce3c7488375b1fd539420d7654bb 008cb88edb41f3c7c8e0ed763ff9f26719830984 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0b5877a1aeacdbf32b3bea91326592004ec7806f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a037ebbe72a4f98495b193112e2b2000e5e09eb5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.12.19 5.13 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.13.4 5.14 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.14","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.14 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.218 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.185 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.154 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.106 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.47 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.11 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.1 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/pci/controller/pci-host-generic.c","drivers/pci/ecam.c","include/linux/pci-ecam.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"5e52eb0290f66ba0732956dcb1e365b5ca3c5108","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"baf9b0383ff770fdff123d3a832f3a99641d96dd","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"8d08713ec83a18526d1ed1fd5f0d2b901d103a10","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"74456843f18ba7f3045974d7e8b88ab993152b8c","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"0c55707bd5d0d7670704cfd0dda933809b052f67","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"a199293f3038db8d31d47aa60f1e18272cd82354","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"0916948026f623844acd08888f7cbedbf1c48d6b","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"lessThan":"008cb88edb41f3c7c8e0ed763ff9f26719830984","status":"affected","version":"8fe55ef23387ce3c7488375b1fd539420d7654bb","versionType":"git"},{"status":"affected","version":"0b5877a1aeacdbf32b3bea91326592004ec7806f","versionType":"git"},{"status":"affected","version":"a037ebbe72a4f98495b193112e2b2000e5e09eb5","versionType":"git"},{"lessThan":"5.13","status":"affected","version":"5.12.19","versionType":"semver"},{"lessThan":"5.14","status":"affected","version":"5.13.4","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/pci/controller/pci-host-generic.c","drivers/pci/ecam.c","include/linux/pci-ecam.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.14"},{"lessThan":"5.14","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.218","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.185","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.154","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.106","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.47","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.11","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.1","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.218","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.185","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.154","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.106","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.47","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.11","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.1","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.14","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.19","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13.4","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus\nand ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n  ra : pci_generic_config_read+0x2c/0xb0\n [<c038db9c>] pci_generic_config_read+0x40/0xb0\n [<c038da04>] pci_bus_read_config_dword+0x50/0xb0\n [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [<c039245c>] pci_scan_single_device+0xa4/0x11c\n [<c0392570>] pci_scan_slot+0x9c/0x23c\n [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4\n [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8\n [<c0393e54>] pci_host_probe+0x20/0xc8\n [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]"}],"providerMetadata":{"dateUpdated":"2026-09-09T16:13:15.202Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108"},{"url":"https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd"},{"url":"https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10"},{"url":"https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c"},{"url":"https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67"},{"url":"https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354"},{"url":"https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b"},{"url":"https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984"}],"title":"PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80917","datePublished":"2026-09-09T16:13:15.202Z","dateReserved":"2026-08-26T14:34:25.801Z","dateUpdated":"2026-09-09T16:13:15.202Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-09 17:17:46","lastModifiedDate":"2026-09-09 17:17:46","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80917","Ordinal":"1","Title":"PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM sy","CVE":"CVE-2026-80917","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80917","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus\nand ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n  ra : pci_generic_config_read+0x2c/0xb0\n [<c038db9c>] pci_generic_config_read+0x40/0xb0\n [<c038da04>] pci_bus_read_config_dword+0x50/0xb0\n [<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [<c039245c>] pci_scan_single_device+0xa4/0x11c\n [<c0392570>] pci_scan_slot+0x9c/0x23c\n [<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4\n [<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8\n [<c0393e54>] pci_host_probe+0x20/0xc8\n [<c03bc6f4>] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]","Type":"Description","Title":"PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM sy"}]}}}