CVE-2026-90082

Source
https://cve.org/CVERecord?id=CVE-2026-90082
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90082.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90082
Downstream
Published
2026-09-17T16:05:59Z
Modified
2026-09-18T03:48:35Z
Summary
net: mana: Cap MSI-X vectors to the device MSI-X table size
Details

In the Linux kernel, the following vulnerability has been resolved:

net: mana: Cap MSI-X vectors to the device MSI-X table size

mana_gd_query_max_resources() sizes gc->num_msix_usable from resp.max_msix and the CPU count, but never from the device MSI-X table. On a 1792 vCPU M-series VM that yields 1793 while the table has 1024 entries, and mana_gd_setup_remaining_irqs() then walks indices 1..1792, running off the end of the region mapped by msix_map_region():

BUG: unable to handle page fault for address: ff8e347f8b99800c RIP: 0010:msix_prepare_msi_desc+0x7a/0x90 RAX: 0000000000004000 RBX: ff4330cb164ea780 RCX: ff8e347f8b998000 Call Trace: __msi_domain_alloc_irqs+0x13a/0x440 msi_domain_alloc_irq_at+0x149/0x1b0 mana_gd_setup+0x351/0x890 mana_gd_probe+0x274/0x390

RAX is index 1024 * PCI_MSIX_ENTRY_SIZE, one entry past the table.

msi_insert_desc() does range check the index, but only against the MSI domain hwsize, which matches the table only for devices on an MSI parent domain. With a global PCI/MSI domain hwsize is MSI_XA_DOMAIN_SIZE, so nothing bounds the request.

Cap num_msix_usable with pci_msix_vec_count().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90082.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
755391121038c06cb653241aa94dcabd87179f62
Fixed
4f9827b314ee57cd99f86f8dbadcaf567112e2b2
Fixed
2c7493f980140a5c40eb4f98f97c557193a2c330

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90082.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90082.json"