In the Linux kernel, the following vulnerability has been resolved:
PCI/IOV: Skip VF Resizable BAR restore on read error
sriovrestorevfrebarstate() uses the VF Resizable BAR Control register to decide how many VF BARs to restore (nbars) and which VF BAR each iteration addresses (baridx). baridx indexes into dev->sriov->barsz[], which has only PCISRIOVNUM_BARS (6) entries.
When a device does not respond, config reads typically return PCIERRORRESPONSE (~0). Both fields are 3 bits wide, so nbars and bar_idx both evaluate to 7. The barsz[] access then goes out of bounds. UBSAN reports this as:
UBSAN: array-index-out-of-bounds in drivers/pci/iov.c:948:51 index 7 is out of range for type 'resourcesizet [6]'
Observed on an NVIDIA RTX PRO 1000 GPU (GB207GLM) that stopped responding during a failed GC6 power state exit. The subsequent pcirestorestate() invoked sriovrestorevfrebarstate() while config reads returned 0xffffffff, triggering the splat.
Bail out if any VF Resizable BAR Control read returns PCIERRORRESPONSE. No further VF BARs are touched, which is safe because a config read that returns PCIERRORRESPONSE indicates the device is unreachable and restoration is pointless. This mirrors the guard in pcirestorerebar_state().
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64460.json",
"cna_assigner": "Linux"
}