CVE-2026-93815
Błąd w jądrze Linuxa w au1000 pozwalał na wywołanie funkcji, która może zasnąć, trzymając spinlock.
In the Linux kernel, the following vulnerability has been resolved: net: au1000: move free_irq out of the close-time spinlocked section au1000_close() calls free_irq() while aup->lock is still held with spin_lock_irqsave(). free_irq() can sleep because it takes the IRQ descriptor request mutex, so it does not belong inside the close-time spinlocked section. This was found by our static analysis tool and then confirmed by manual review of the in-tree au1000_close() .ndo_stop path. The reviewed path keeps aup->lock held across the MAC reset, queue stop and free_irq(dev->irq, dev). A directed runtime validation kept that ndo_stop carrier and the same free_irq(dev->irq, dev) operation under the driver lock. Lockdep reported "BUG: sleeping function called from invalid context" and "Invalid wait context" while free_irq() was taking desc->request_mutex, with au1000_close() and free_irq() on the stack. Drop aup->lock before freeing the IRQ. The protected close-time work still stops the device and queue before IRQ teardown, but the sleepable IRQ core path now runs outside the spinlocked section.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 0.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-24 17:17:15 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-03 11:17:51 UTC |
- https://git.kernel.org/stable/c/26fd652915123a690f19d62b253b545a53f3cd51 (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/4536667fba8ddbaff2f2a135080ae6aabf737b5e (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/d514b08ed61fdffe23604fd3e9e53c07cbe5ac3e (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/e1b5a13249975fec3cf654efa84f57118db2da2c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/f48763beab4eea41fc480c9702ec6eebe8d75e4f (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/f86bca5b7857b85bfa8afdb4fa895d7c0a3f7ebc (416baaa9-dc9f-4396-8d5f-8c081fb06d67)
- https://git.kernel.org/stable/c/fc2233f1ab2a1ca562869bca6987d7477671388c (416baaa9-dc9f-4396-8d5f-8c081fb06d67)