CVE-2026-63977 Details
Description
In the Linux kernel, the following vulnerability has been resolved: dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work The change_work was introduced to send device change notifications from DPLL device callbacks without deadlocking on dpll_lock, since the callbacks are already invoked under that lock. Now that __dpll_device_change_ntf() is exported for callers that already hold dpll_lock, use it directly and remove the change_work infrastructure entirely. This eliminates a race condition where change_work could be re-scheduled after cancel_work_sync() during device teardown, potentially causing the handler to dereference a freed or NULL dpll_dev pointer.
A race condition vulnerability has been identified in the Linux kernel's DPLL (Digital Phase-Locked Loop) subsystem, specifically within the zl3073x driver. This vulnerability arises from the improper handling of device change notifications, which could lead to dereferencing a freed or null pointer during device teardown. The issue has been resolved by eliminating the change_work infrastructure and directly using the __dpll_device_change_ntf() function, which is now available for callers that hold the appropriate lock.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/d733f519f6443540f8359461a34e3b0042099bbe | kernel.org | |
| https://git.kernel.org/stable/c/e7a33807fb3f87a855993474ac21684ce105927b | kernel.org |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | kernel.org |
| Jul 19, 2026 | New CVE Received | kernel.org |