-

CVE-2026-74468

gpio: pch: use raw_spinlock_t for the register lock

In the Linux kernel, the following vulnerability has been resolved:

gpio: pch: use raw_spinlock_t for the register lock

pch_irq_type() is registered as the irq_chip .irq_set_type callback and
takes chip->spinlock with spin_lock_irqsave().  This callback is reached
from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while
the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled.
That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is
an rtmutex-backed sleeping lock, so acquiring it there is invalid.

This was confirmed on a PREEMPT_RT kernel with lockdep
(PROVE_RAW_LOCK_NESTING and DEBUG_ATOMIC_SLEEP).  A grounded PoC mirrored
pch_irq_type()'s locking and drove it through the real genirq carrier
irq_set_irq_type() -> __irq_set_trigger() -> chip->irq_set_type(), i.e.
the same __irq_set_trigger() edge that __setup_irq() takes for a
requested IRQ.  With the original spin_lock_irqsave() edge lockdep
reported an invalid wait context, immediately followed by:

  BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48
  in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 95, name: insmod
  hardirqs last disabled at (3784): _raw_spin_lock_irqsave+0x4f/0x60
   rt_spin_lock+0x3a/0x1c0
   repro_irq_set_type+0x64/0xa0 [pch_repro]
   __irq_set_trigger+0x69/0x140
   irq_set_irq_type+0x78/0xd0

Switching the mirrored lock to raw_spinlock_t made both splats go away.

Convert the register lock to raw_spinlock_t.  The same lock also
serializes the GPIO direction/value callbacks and the suspend/resume
register save/restore, but all of those critical sections only perform
MMIO register accesses (ioread32()/iowrite32()) and
irq_set_handler_locked(); none of them contain sleepable operations.
Keeping this register lock non-sleeping is therefore appropriate for the
irqchip callbacks and does not change the GPIO-side locking contract.

This is the same class of issue and fix as recently addressed for other
GPIO controllers, e.g. commit 286533cb14a3 ("gpio: sch: use raw_spinlock_t
in the irq startup path") and commit 90f0109019e6 ("gpio: eic-sprd: use
raw_spinlock_t in the irq startup path").
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < efc76a3f5353dd33a2e2ad48200cd4a18de30a0d
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < 935e6872db7faecfbe1a10b3f5d97a62fdff5ec9
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < 98f292cb6d01487d17988d9fd4e19c13e7adb156
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < 16da33cb36e663b6967112185e11d00ce8ff957c
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < ff050589a21967883bb55f6dba42568f8367ad4a
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < 466ab0c41d5f54f71cee60619d07c4abd0ffd2cd
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < c0a4ec89fc26e4b679b04f1002c503cb2529acdc
Status affected
Version 38eb18a6f92da886fc1af509d25e8f7a49e23d9a
Version < a02b8950d619123da64f69b70fe1dadef217dfe4
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.2
Status affected
Version 0
Version < 3.2
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/16da33cb36e663b6967112185e11d00ce8ff957c
https://git.kernel.org/stable/c/ff050589a21967883bb55f6dba42568f8367ad4a
https://git.kernel.org/stable/c/466ab0c41d5f54f71cee60619d07c4abd0ffd2cd
https://git.kernel.org/stable/c/c0a4ec89fc26e4b679b04f1002c503cb2529acdc
https://git.kernel.org/stable/c/a02b8950d619123da64f69b70fe1dadef217dfe4
https://git.kernel.org/stable/c/935e6872db7faecfbe1a10b3f5d97a62fdff5ec9
https://git.kernel.org/stable/c/98f292cb6d01487d17988d9fd4e19c13e7adb156
https://git.kernel.org/stable/c/efc76a3f5353dd33a2e2ad48200cd4a18de30a0d