Back

MEDIUM

PCI: endpoint: Avoid creating sub-groups asynchronously

Published Feb 18, 2026

Description

The asynchronous creation of sub-groups by a delayed work could lead to a NULL pointer dereference when the driver directory is removed before the work completes.

The crash can be easily reproduced with the following commands:

# cd /sys/kernel/config/pci_ep/functions/pci_epf_test # for i in {1..20}; do mkdir test && rmdir test; done

BUG: kernel NULL pointer dereference, address: 0000000000000088 ... Call Trace: configfs_register_group+0x3d/0x190 pci_epf_cfs_work+0x41/0x110 process_one_work+0x18f/0x350 worker_thread+0x25a/0x3a0

Fix this issue by using configfs_add_default_group() API which does not have the deadlock problem as configfs_register_group() and does not require the delayed work handler.

[mani: slightly reworded the description and added stable list]

Affected products

Remediation

Red Hat statement

A NULL pointer dereference can occur in the PCI endpoint configfs code because sub groups were created asynchronously using delayed work. If a user removes the driver directory before the delayed work runs the work handler can call configfs_register_group on freed or partially torn down objects and crash the kernel. For the CVSS the PR is H because writing to configfs and creating PCI endpoint function entries typically requires administrative privileges. The issue is not network reachable and is triggered by local filesystem operations on configfs entries. Impact is denial of service through a kernel crash and there is no clear indication of confidentiality or integrity impact from this NULL dereference.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Feb 18, 2026
Updated May 11, 2026
Reserved Feb 18, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 18, 2026
ENISA EUVD
Assigner Linux
Published Feb 18, 2026
Updated May 11, 2026
Exploited since n/a
EUVD-2025-207665