[SRU][J][PATCH 0/1] CVE-2025-38239

Cengiz Can cengiz.can at canonical.com
Thu Sep 10 21:20:48 UTC 2026


https://ubuntu.com/security/CVE-2025-38239

[ Impact ]

In the Linux kernel, the following vulnerability has been resolved:

scsi: megaraid_sas: Fix invalid node index

On a system with DRAM interleave enabled, out-of-bound access is detected:

megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0
------------[ cut here ]------------ UBSAN: array-index-out-of-bounds in
./arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type
'cpumask *[1024]' dump_stack_lvl+0x5d/0x80 ubsan_epilogue+0x5/0x2b
__ubsan_handle_out_of_bounds.cold+0x46/0x4b
megasas_alloc_irq_vectors+0x149/0x190 [megaraid_sas]
megasas_probe_one.cold+0xa4d/0x189c [megaraid_sas] local_pci_probe+0x42/0x90
pci_device_probe+0xdc/0x290 really_probe+0xdb/0x340
__driver_probe_device+0x78/0x110 driver_probe_device+0x1f/0xa0
__driver_attach+0xba/0x1c0 bus_for_each_dev+0x8b/0xe0
bus_add_driver+0x142/0x220 driver_register+0x72/0xd0 megasas_init+0xdf/0xff0
[megaraid_sas] do_one_initcall+0x57/0x310 do_init_module+0x90/0x250
init_module_from_file+0x85/0xc0 idempotent_init_module+0x114/0x310
__x64_sys_finit_module+0x65/0xc0 do_syscall_64+0x82/0x170
entry_SYSCALL_64_after_hwframe+0x76/0x7e

Fix it accordingly.

When the megaraid_sas driver allocates its interrupt vectors it queries the
NUMA node of the controller's PCI device to build a per-node CPU mask for
IRQ affinity. On configurations where the node cannot be determined the
lookup returns NUMA_NO_NODE (-1), and that value was used directly as an
index into a per-node array, producing the out-of-bounds access reported by
UBSAN during driver probe.

The fix guards the node value: when the returned node is NUMA_NO_NODE it is
replaced with node 0 before being used to index the array, keeping the
access within bounds.

[ Fix ]

jammy/linux: backported from 752eb816b55a

[ Test Plan ]

Build and boot tested.

[ Where Problems Could Occur ]

A regression from this change would be confined to systems using Broadcom/LSI
MegaRAID SAS controllers driven by megaraid_sas, particularly multi-socket
NUMA machines (for example with DRAM interleave enabled) where interrupt
affinity is derived from the controller's NUMA node; a mistake here could
misdirect IRQ affinity hints or affect driver probe. Systems without a
megaraid_sas controller do not load this driver and are not affected.

[ Other Info ]

Kybele flow-v11-25-ga27c0fa6. Reference: 4af6345d/v1



More information about the kernel-team mailing list