-

CVE-2026-90193

mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

In the Linux kernel, the following vulnerability has been resolved:

mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding
chan->lock. Under PREEMPT_RT, spin_lock_irqsave() is converted to an
rt_spinlock (rtmutex-based), which tracks ownership and can sleep.

The callback chain triggered by mbox_chan_received_data() eventually
reaches mailbox_clear_channel() -> mbox_send_message() -> add_to_rbuf(),
which attempts to re-acquire the same chan->lock. Since rtmutex detects
the re-entrant lock attempt by the same owner, the thread blocks waiting
for a lock it already holds, causing a permanent deadlock.

This deadlock manifests as 'irq/N-apss_cpucp_mbox' stuck in D state
with the following call trace:
  rt_spin_lock -> mbox_send_message -> mailbox_clear_channel ->
  scmi_rx_callback -> mbox_chan_received_data [<- held chan->lock here]

Fix by saving chan->cl locally and clearing the HW interrupt register
inside the lock, then invoking mbox_chan_received_data() after releasing
the lock. This preserves the mutual exclusion for chan->cl access while
avoiding the lock re-entrancy that causes the PREEMPT_RT deadlock.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 0e2a9a03106cd5fa0dbc9047675e7645c55e2669
Version < aa482273f32117c3adeba9b1cc945e0b5d33722d
Status affected
Version 0e2a9a03106cd5fa0dbc9047675e7645c55e2669
Version < 8b8de6400c86937ed57d680d06d716e167b381de
Status affected
Version 0e2a9a03106cd5fa0dbc9047675e7645c55e2669
Version < e40b3edeaf25cd09e9c88edb1ef99373ca37593b
Status affected
Version 0e2a9a03106cd5fa0dbc9047675e7645c55e2669
Version < 3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/aa482273f32117c3adeba9b1cc945e0b5d33722d
https://git.kernel.org/stable/c/8b8de6400c86937ed57d680d06d716e167b381de
https://git.kernel.org/stable/c/e40b3edeaf25cd09e9c88edb1ef99373ca37593b
https://git.kernel.org/stable/c/3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c