CVE-2026-64148

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> pds_core: fix error handling in pdsc_devcmd_wait<br /> <br /> Fix two cases where pdsc_devcmd_wait() returns stale success from<br /> the completion register instead of an error:<br /> <br /> 1. FW crash: If firmware stops running, the wait loop breaks early with<br /> running=false. The condition "if ((!done || timeout) &amp;&amp; running)" is<br /> false, so error handling is bypassed and stale status is returned.<br /> Check !running first and return -ENXIO.<br /> <br /> 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then<br /> overwritten by pdsc_err_to_errno(status) which reads stale status.<br /> Return -ETIMEDOUT immediately after cleaning up.<br /> <br /> Both errors now propagate to pdsc_devcmd_locked() which queues<br /> health_work for recovery.