CVE-2026-68319

In the Linux kernel, the following vulnerability has been resolved: pds_core: fix deadlock between reset thread and remove pci_reset_function() acquires device_lock before performing the reset. pdsc_remove() is called by the PCI core with device_lock already held. If pdsc_pci_reset_thread() is running when pdsc_remove() is called, destroy_workqueue() will block waiting for the work to complete, while the work is blocked waiting for device_lock - deadlock. Use pci_try_reset_function() which uses pci_dev_trylock() internally. This acquires both the device lock and the PCI config access lock without blocking - if either lock is contended, it returns -EAGAIN immediately. This avoids the deadlock while also ensuring proper config space access serialization during the reset. The pci_dev_get/put calls are also removed as they were unnecessary - the driver-owned workqueue is destroyed in pdsc_remove(), guaranteeing the work completes before remove returns. The PCI core holds its reference to pci_dev throughout the entire unbind sequence.

Package Linux Kernel
Published 2026-08-10
Last modified 2026-08-17
Patch available
Yes

Affected versions

Linux kernel versions 6.8.7, 6.9 and later are affected. Fixed in 6.12.101, 6.18.42, 7.1.6, 7.2 and their respective stable series.

Affected from
≥ 6.8.7 ≥ 6.9
Fixed in
✓ 6.12.101 6.12.x ✓ 6.18.42 6.18.x ✓ 7.1.6 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-68319?

    CVE-2026-68319 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.8.7 onward and has been patched in 6.12.101, 6.18.42, 7.1.6 and others. CVE-2026-68319 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-68319?

    Yes. CVE-2026-68319 has been patched. Fixed versions include 6.12.101, 6.18.42, 7.1.6 and others. If you are running Linux kernel 6.8.7 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-68319 actively exploited?

    No. CVE-2026-68319 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.