SB20260916139 - Race condition in Linux kernel parisc
Published: September 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-89980)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.
The vulnerability exists due to a race condition involving uninitialized locks in the ALSA Harmony driver when a pending interrupt is handled after IRQ registration and before lock initialization. A remote attacker can trigger a pending interrupt during device initialization to compromise confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/33abb7491e89285a41565670945293dda841afc4
- https://git.kernel.org/stable/c/7dc239edb6d58e01c9ec868565cc03e7adf91747
- https://git.kernel.org/stable/c/89992bda7dfbba7ded2ba4185730453c57fa65bc
- https://git.kernel.org/stable/c/9347588bbd6ad43a85e17046d9c117a41453c52a
- https://git.kernel.org/stable/c/9af6c9203583655cb7ed45e52e14101652b37547
- https://git.kernel.org/stable/c/cd209eb3136e002becbda232e399fa31a2276436
- https://git.kernel.org/stable/c/f86ff9238b0c8284909e073a681a60708b9f36ab