{"id":"CVE-2026-98142","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/cirrus-qemu: Validate BAR0 size during probe\n\nThe `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate\nframebuffer sizes","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/cirrus-qemu: Validate BAR0 size during probe\n\nThe `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate\nframebuffer sizes. However, during PCI probe,…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 0b5084a1f070ad1fc34e11945644ae034bbc774c","Linux >= ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 26bd90c886218f36c9adeab206b0e27b4384e2f6","Linux >= ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 144f51cd0ccc3ad47a6099917b7bb535611fb18f","Linux >= ab3e023b1b4c9887c9f0f761b47f3f0516bd3434 < 92312d333bf700798f92f30406c721bce87506f3","Linux 5.2"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T11:17:45.710","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98142","references":[{"url":"https://git.kernel.org/stable/c/0b5084a1f070ad1fc34e11945644ae034bbc774c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/144f51cd0ccc3ad47a6099917b7bb535611fb18f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/26bd90c886218f36c9adeab206b0e27b4384e2f6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92312d333bf700798f92f30406c721bce87506f3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.809Z","slug":"CVE-2026-98142","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ndrm/cirrus-qemu: Validate BAR0 size during probe\n\nThe `cirrus-qemu` driver relies on `CIRRUS_VRAM_SIZE` (4 MB) to validate\nframebuffer sizes. However, during PCI probe, the driver mapped BAR0\nwithout verifying that its size matches `CIRRUS_VRAM_SIZE`.\n\nIf a PCI device with a BAR0 smaller than 4 MB is bound to the driver, the\nmapped VRAM will be smaller than expected. Because validation checks assume\n4 MB VRAM, framebuffers larger than the mapped memory can be created.\n\nWhen the display plane is updated (e.g. during release),\n`cirrus_primary_plane_helper_atomic_update()` copies the framebuffer to\nVRAM using `drm_fb_memcpy()`. Writing past the end of the mapped I/O memory\ncauses a supervisor write page fault:\n\nBUG: unable to handle page fault for address: ffffc9000389c000\n...\nRIP: 0010:memcpy_toio+0x7c/0xe0 arch/x86/lib/iomem.c:110\n...\nCall Trace:\n <TASK>\n iosys_map_memcpy_to include/linux/iosys-map.h:285 [inline]\n drm_fb_memcpy+0x325/0x5d0 drivers/gpu/drm/drm_format_helper.c:442\n cirrus_primary_plane_helper_atomic_update+0x98a/0xb00\n drivers/gpu/drm/tiny/cirrus-qemu.c:358\n drm_atomic_helper_commit_planes+0x626/0xea0\n drivers/gpu/drm/drm_atomic_helper.c:3038\n drm_atomic_helper_commit_tail+0x60/0x510\n drivers/gpu/drm/drm_atomic_helper.c:1989\n commit_tail+0x2b1/0x3c0 drivers/gpu/drm/drm_atomic_helper.c:2074\n drm_atomic_helper_commit+0xa77/0xb10\n drivers/gpu/drm/drm_atomic_helper.c:2312\n\nFix this by validating in `cirrus_pci_probe()` that the PCI BAR0 resource\nis not less than `CIRRUS_VRAM_SIZE`, returning `-ENODEV` if it is less.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}