CVE-2026-64429 Details
Description
In the Linux kernel, the following vulnerability has been resolved: gpio: eic-sprd: use raw_spinlock_t in the irq startup path sprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller state through sprd_eic_update(), which takes sprd_eic->lock with spin_lock_irqsave(). The callback can be reached from irq_startup() while setting up a requested IRQ. That path is not sleepable, but on PREEMPT_RT a regular spinlock_t becomes a sleeping lock. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the request_threaded_irq() -> __setup_irq() -> irq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and used the original spin_lock_irqsave(&sprd_eic->lock) edge. Lockdep BUG: sleeping function called from invalid context hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv] sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv] sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv] sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv] __setup_irq.constprop.0+0xd/0x30 [vuln_msv] Convert the Spreadtrum EIC controller lock to raw_spinlock_t. The locked section only serializes MMIO register updates and does not contain sleepable operations, so keeping it non-sleeping is appropriate for the irqchip callbacks.
A vulnerability exists in the Linux kernel's handling of GPIO interrupts for the Spreadtrum EIC controller. The issue arises because the IRQ unmasking function, 'sprd_eic_irq_unmask()', enables the GPIO IRQ and subsequently updates the controller state using 'sprd_eic_update()'. This update process involves a regular spinlock, which can lead to sleeping in a non-sleepable context on PREEMPT_RT kernels. The vulnerability was identified through static analysis and can be reproduced by simulating the IRQ setup process, which triggers a Lockdep error about sleeping functions being called from an invalid context. The problem has been addressed by changing the lock type to 'raw_spinlock_t', which is appropriate for IRQ chip callbacks and prevents sleeping in critical contexts.
The vulnerability has been fixed by changing the lock initialization and usage from 'spinlock_t' to 'raw_spinlock_t', ensuring that the lock does not cause sleeping inappropriately during IRQ handling.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a | kernel.org | Patch |
| https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a | kernel.org | Patch |
| https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e | kernel.org | Patch |
| https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd | kernel.org | Patch |
| https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29 | kernel.org | Patch |
| https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.17, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 3, 2026 | Initial Analysis | [email protected] |
| Aug 17, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |