SB20260727132 - Improper locking in Linux kernel gpio driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper locking (CVE-ID: CVE-2026-64429)
CWE-ID: CWE-667 - Improper Locking
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock handling in the Spreadtrum EIC GPIO interrupt controller driver when starting up a requested IRQ on PREEMPT_RT systems. A local user can request a threaded IRQ to trigger a sleeping lock in an invalid context to cause a denial of service.
The issue occurs because the callback can be reached from a non-sleepable irq_startup() path.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a
- https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7
- https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a
- https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e
- https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd
- https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29
- https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628
- https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739