---
id: CVE-2026-43344
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  perf/x86/intel/uncore: Fix die ID init and look up bugs

  In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,
  uncore_device_to_die() may return -1 when all CPUs as…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  perf/x86/intel/uncore: Fix die ID init and look up bugs

  In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,
  uncore_device_to_die() may return -1 when all CPUs as…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-617
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 5.12, < 6.19.14'
  - linux_kernel = 7.0
patched:
  - linux_kernel 6.19.14
published: '2026-05-08'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T12:17:41.427'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-43344'
references:
  - url: 'https://git.kernel.org/stable/c/184870af0e73f8ea2577c751fa098681465249f2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6a5dc3ee97581da2907fc7acd62853f07184de67'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a16d1ec4dd0cdcf689f324adde6067083bce9099'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/bdb35811ff41a1678620a407056b6372f350028a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c79ef3342632e71ac8612a2a1cc17ac84dd258b4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00162
epssPercentile: 0.04603
ingestedAt: '2026-09-07T17:14:51.573Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

perf/x86/intel/uncore: Fix die ID init and look up bugs

In snbep_pci2phy_map_init(), in the nr_node_ids > 8 path,
uncore_device_to_die() may return -1 when all CPUs associated
with the UBOX device are offline.

Remove the WARN_ON_ONCE(die_id == -1) check for two reasons:

- The current code breaks out of the loop. This is incorrect because
  pci_get_device() does not guarantee iteration in domain or bus order,
  so additional UBOX devices may be skipped during the scan.

- Returning -EINVAL is incorrect, since marking offline buses with
  die_id == -1 is expected and should not be treated as an error.

Separately, when NUMA is disabled on a NUMA-capable platform,
pcibus_to_node() returns NUMA_NO_NODE, causing uncore_device_to_die()
to return -1 for all PCI devices.  As a result,
spr_update_device_location(), used on Intel SPR and EMR, ignores the
corresponding PMON units and does not add them to the RB tree.

Fix this by using uncore_pcibus_to_dieid(), which retrieves topology
from the UBOX GIDNIDMAP register and works regardless of whether NUMA
is enabled in Linux.  This requires snbep_pci2phy_map_init() to be
added in spr_uncore_pci_init().

Keep uncore_device_to_die() only for the nr_node_ids > 8 case, where
NUMA is expected to be enabled.

## Affected

- `linux_kernel >= 5.12, < 6.19.14`
- `linux_kernel = 7.0`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.19.14`
