ACK: [SRU][J][PATCH 0/1] CVE-2025-38239

Edoardo Canepa edoardo.canepa at canonical.com
Tue Sep 15 20:09:55 UTC 2026


Acked-by: Edoardo Canepa <edoardo.canepa at canonical.com>

On 9/10/26 23:20, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2025-38239
>
> [ Impact ]
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> scsi: megaraid_sas: Fix invalid node index
>
> On a system with DRAM interleave enabled, out-of-bound access is detected:
>
> megaraid_sas 0000:3f:00.0: requested/available msix 128/128 poll_queue 0
> ------------[ cut here ]------------ UBSAN: array-index-out-of-bounds in
> ./arch/x86/include/asm/topology.h:72:28 index -1 is out of range for type
> 'cpumask *[1024]' dump_stack_lvl+0x5d/0x80 ubsan_epilogue+0x5/0x2b
> __ubsan_handle_out_of_bounds.cold+0x46/0x4b
> megasas_alloc_irq_vectors+0x149/0x190 [megaraid_sas]
> megasas_probe_one.cold+0xa4d/0x189c [megaraid_sas] local_pci_probe+0x42/0x90
> pci_device_probe+0xdc/0x290 really_probe+0xdb/0x340
> __driver_probe_device+0x78/0x110 driver_probe_device+0x1f/0xa0
> __driver_attach+0xba/0x1c0 bus_for_each_dev+0x8b/0xe0
> bus_add_driver+0x142/0x220 driver_register+0x72/0xd0 megasas_init+0xdf/0xff0
> [megaraid_sas] do_one_initcall+0x57/0x310 do_init_module+0x90/0x250
> init_module_from_file+0x85/0xc0 idempotent_init_module+0x114/0x310
> __x64_sys_finit_module+0x65/0xc0 do_syscall_64+0x82/0x170
> entry_SYSCALL_64_after_hwframe+0x76/0x7e
>
> Fix it accordingly.
>
> When the megaraid_sas driver allocates its interrupt vectors it queries the
> NUMA node of the controller's PCI device to build a per-node CPU mask for
> IRQ affinity. On configurations where the node cannot be determined the
> lookup returns NUMA_NO_NODE (-1), and that value was used directly as an
> index into a per-node array, producing the out-of-bounds access reported by
> UBSAN during driver probe.
>
> The fix guards the node value: when the returned node is NUMA_NO_NODE it is
> replaced with node 0 before being used to index the array, keeping the
> access within bounds.
>
> [ Fix ]
>
> jammy/linux: backported from 752eb816b55a
>
> [ Test Plan ]
>
> Build and boot tested.
>
> [ Where Problems Could Occur ]
>
> A regression from this change would be confined to systems using Broadcom/LSI
> MegaRAID SAS controllers driven by megaraid_sas, particularly multi-socket
> NUMA machines (for example with DRAM interleave enabled) where interrupt
> affinity is derived from the controller's NUMA node; a mistake here could
> misdirect IRQ affinity hints or affect driver probe. Systems without a
> megaraid_sas controller do not load this driver and are not affected.
>
> [ Other Info ]
>
> Kybele flow-v11-25-ga27c0fa6. Reference: 4af6345d/v1
>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260915/938efadd/attachment-0001.sig>


More information about the kernel-team mailing list