{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.5-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Revert \"PCI/MSI: Unmap MSI-X region on error\"  This reverts commit 1a8d4c6ecb4c81261bcdf13556abd4a958eca202.  Commit 1a8d4c6ecb4c (\"PCI/MSI: Unmap MSI-X region on error\") added an iounmap(dev-\u003emsix_base) on the error path of msix_capability_init() to release the MSI-X region when msix_setup_interrupts() fails.  When msix_setup_interrupts() fails, the call chain is:    msix_setup_interrupts()     -\u003e __msix_setup_interrupts()          struct pci_dev *dev __free(free_msi_irqs) = __dev;          ...          return ret;  // __free cleanup fires on error  The __free(free_msi_irqs) cleanup calls pci_free_msi_irqs(), which already handles the unmap:    void pci_free_msi_irqs(struct pci_dev *dev)   {       pci_msi_teardown_msi_irqs(dev);       if (dev-\u003emsix_base) {           iounmap(dev-\u003emsix_base);   // already unmapped here           dev-\u003emsix_base = NULL;     // and set to NULL       }   }  So dev-\u003emsix_base is unmapped and set to NULL before msix_setup_interrupts() returns to msix_capability_init(). The \"goto out_unmap\" introduced by commit 1a8d4c6ecb4c (\"PCI/MSI: Unmap MSI-X region on error\") then calls iounmap() a second time on a NULL pointer.  This was reproduced on Intel Emerald Rapids (192 CPUs) while running tools/testing/selftests/kexec/test_kexec_jump.sh:    WARNING: CPU#44 at iounmap+0x2a/0xe0   RIP: 0010:iounmap+0x2a/0xe0   RDI: 0000000000000000   Call Trace:    msix_capability_init+0x317/0x3f0    __pci_enable_msix_range+0x21d/0x2c0    pci_alloc_irq_vectors_affinity+0xa9/0x130    nvme_setup_io_queues+0x2a8/0x420 [nvme]    nvme_reset_work+0x151/0x340 [nvme]    ...  RDI=0 confirms iounmap() is called with NULL.  Restore the original \"goto out_disable\" and leave the unmap to the existing __free(free_msi_irqs) cleanup.",
  "id": "DEBIAN-CVE-2026-80620",
  "modified": "2026-09-14T16:47:48.838645386Z",
  "published": "2026-08-28T08:16:46.083Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80620"
    }
  ],
  "upstream": [
    "CVE-2026-80620"
  ]
}