-

CVE-2026-93259

powerpc/irq: Fix missing r2 clobber in PCREL inline assembly

In the Linux kernel, the following vulnerability has been resolved:

powerpc/irq: Fix missing r2 clobber in PCREL inline assembly

In CONFIG_PPC_KERNEL_PCREL mode, r2 is no longer reserved for the TOC
pointer and is available as a caller-saved register [0].

Both call_do_irq() and call_do_softirq() use inline assembly to call
functions with stack switching, but fail to list r2 in their clobber
lists. This causes the compiler to assume r2 is preserved across these
calls, leading to register corruption when the called functions
(__do_irq and __do_softirq) clobber r2.

As a result of this kernel crash during interrupt handling is seen and
the kernel fails to boot:

BUG: Unable to handle kernel data access on write at 0xc000000404697638
Faulting instruction address: 0xc0000000000181ec
Oops: Kernel access of bad area, sig: 11 [#1]
NIP [c0000000000181ec] __do_IRQ+0x6c/0xc0

With older GCC, the compiler would conservatively allocate
callee-saved registers (like r31) for values spanning function calls,
accidentally avoiding the bug:

<__do_IRQ>:
00 00 00 60 	nop
a6 02 08 7c 	mflr    r0
f8 ff e1 fb 	std     r31,-8(r1)
f0 ff c1 fb 	std     r30,-16(r1)
2d 03 10 06 	pla     r31,53297316

...

3d e8 ff 4b 	bl      c0000000000165ac <__do_irq>
00 00 21 e8 	ld      r1,0(r1)
28 00 4d e9 	ld      r10,40(r13)
40 00 21 38 	addi    r1,r1,64
2a f9 aa 7f 	stdx    r29,r10,r31

With newer GCC 14, the compiler uses r2 for such values, exposing the
missing clobber specification:

<__do_IRQ>:
00 00 00 60     nop
a6 02 08 7c     mflr    r0
f0 ff c1 fb     std     r30,-16(r1)
f8 ff e1 fb     std     r31,-8(r1)
29 02 10 06     pla     r2,36252592     # c0000000022aadc0 <__irq_regs>

...

85 dc ff 4b 	bl      c000000000015ee0 <__do_irq>
00 00 21 e8 	ld      r1,0(r1)
28 00 2d e9 	ld      r9,40(r13)
30 00 21 38 	addi    r1,r1,48
2a 11 c9 7f 	stdx    r30,r9,r2

Fix this by adding r2 to the clobber list for both call_do_irq() and
call_do_softirq() when CONFIG_PPC_KERNEL_PCREL is enabled.

[0]: https://www.mail-archive.com/gcc-patches@gcc.gnu.org/msg313226.html
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 7e3a68be42e10f5fa5890e97afc0afd992355bc3
Version < dcc442a49c0f540193910dacdca7506bcadc7ec5
Status affected
Version 7e3a68be42e10f5fa5890e97afc0afd992355bc3
Version < 602ee44415f3eaa7893f7fc488c7c1d4a0bdbd7a
Status affected
Version 7e3a68be42e10f5fa5890e97afc0afd992355bc3
Version < 90d953002cf0b233dd053a0e7cb67ab79cebd0e3
Status affected
Version 7e3a68be42e10f5fa5890e97afc0afd992355bc3
Version < 7b0093b638c8f2b94b0778a69fd1ccad54299b29
Status affected
Version 7e3a68be42e10f5fa5890e97afc0afd992355bc3
Version < 00be69070d91d2be978e752bb117a0a4db0e1281
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.4
Status affected
Version 0
Version < 6.4
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.073
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/dcc442a49c0f540193910dacdca7506bcadc7ec5
https://git.kernel.org/stable/c/602ee44415f3eaa7893f7fc488c7c1d4a0bdbd7a
https://git.kernel.org/stable/c/90d953002cf0b233dd053a0e7cb67ab79cebd0e3
https://git.kernel.org/stable/c/7b0093b638c8f2b94b0778a69fd1ccad54299b29
https://git.kernel.org/stable/c/00be69070d91d2be978e752bb117a0a4db0e1281