Linux Kernel PDS Core Error Handling Vulnerability, CVE-2026-64148 (High) -DC-Aug2026-1566

Listen to this Post

CVE-2026-64148 is a vulnerability in the Linux kernel’s PDS Core component, specifically within the `pdsc_devcmd_wait()` function. This function is responsible for waiting on device command completion by polling a completion register. The core issue lies in improper error handling that can lead to the function returning a stale success status instead of a proper error code under two specific failure scenarios.
First scenario – Firmware crash: If the firmware stops running unexpectedly, the wait loop breaks early with the `running` flag set to false. The original conditional check `if ((!done || timeout) && running)` evaluates to `false` because `running` is false, causing the error handling block to be completely bypassed. As a result, `pdsc_devcmd_wait()` returns whatever stale status value happens to be in the completion register, rather than reporting `-ENXIO` (No such device or address) to indicate the firmware failure.
Second scenario – Command timeout: When a device command times out, the function correctly sets `err` to -ETIMEDOUT. However, this error value is subsequently overwritten by a call to pdsc_err_to_errno(status), which reads the (now stale) status from the completion register. This overwrites the timeout error with whatever value `pdsc_err_to_errno()` returns, masking the actual timeout condition.
In both cases, the caller receives a false success indication, preventing proper error propagation. The fix ensures that `!running` is checked first to return -ENXIO, and timeout errors are returned immediately after cleanup without being overwritten. Both errors now correctly propagate to pdsc_devcmd_locked(), which queues `health_work` for recovery.

DailyCVE Form:

Platform: Linux Kernel
Version: 6.6.141/6.12.91/6.18.33/7.0.10
Vulnerability: Stale status return
Severity: 7.5 HIGH
date: 2026-07-19

Prediction: 2026-08-15

What Undercode Say:

Check current kernel version
uname -r
Verify if running a vulnerable version
Vulnerable: 6.6.141, 6.12.91, 6.18.33, 7.0.10
Fixed: 6.6.142, 6.12.92, 6.18.34, 7.0.11
Check if pds_core module is loaded
lsmod | grep pds_core
View PDS device status
cat /sys/class/net/pds/device/status 2>/dev/null
Monitor kernel messages for PDS errors
dmesg | grep -i pds | tail -20
Check for health_work queue events
dmesg | grep -i "health_work" | tail -10

Affected file: `drivers/net/ethernet/amd/pds_core/dev.c`

Fix commits:

– `3231aff8ab26111c54e630b1a200fc43a729dd14`
– `10ae3180095bbe2d378c5b1d6f2f2fd74dda3cc2`
– `784dd2bdc622ed3cc6ef8e113aa1852e252de36f`
– `560d559324169fe0583d54c475b5329550a86f71`
– `0e46b6635b03d29807f810c3b415c4755a3f958d`

Exploit: (Educational Purposes!)

This vulnerability is classified as remotely exploitable with low attack complexity and no privileges required. The attack vector is Network.

Conceptual exploitation scenario:

  1. An attacker sends a crafted command to the PDS device via the network interface
  2. The command triggers a firmware crash or induces a timeout condition
    3. `pdsc_devcmd_wait()` returns stale success status instead of an error
  3. The kernel continues operating under the false assumption that the command succeeded
  4. This can lead to privilege escalation as the kernel may perform privileged operations based on the stale status

CVSS Vector: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`

CWE: CWE-393: Return of Wrong Status Code

EPSS Probability: <1% (as of publication date)

Exploit Price Estimate: $0–$5k

Protection:

Immediate Mitigation:

  • Upgrade to Linux kernel 6.6.142, 6.12.92, 6.18.34, or 7.0.11 or later
  • Apply the patch commits listed above from kernel.org

Distribution-specific fixes:

  • Ubuntu: USN-8603-1
  • Debian: DSA announced
  • Red Hat: CVE entry available

Temporary Workarounds:

  • If unable to patch immediately, consider restricting network access to PDS devices
  • Monitor `dmesg` for PDS-related errors indicating potential exploitation attempts
  • Disable PDS Core functionality if not required (though this may impact network functionality)

Impact:

  • Confidentiality Impact: None
  • Integrity Impact: None
  • Availability Impact: HIGH
    The primary impact is on system availability. A successful exploit could cause the kernel to operate with incorrect state information, potentially leading to system instability, crashes, or denial of service. While the CVSS vector shows no direct impact on confidentiality or integrity, the vulnerability can lead to remote privilege escalation, meaning an attacker could gain elevated privileges on the affected system. The vulnerability is considered very critical by some security metrics, with a VulDB Meta Base Score of 9.9.
    Affected configurations: 23 CPEs across 6 vendors and 6 products

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top