Improper locking in Linux kernel - CVE-2026-45904
Published: May 28, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in EEH event handling when processing PCI error events. A local user can trigger recursive lock acquisition to cause a denial of service.
The issue can lead to deadlock in the pci_rescan_remove_lock path and disrupt normal EEH event handling.
How to mitigate CVE-2026-45904
Sources
- https://git.kernel.org/stable/c/6e6561231c6cfc32c5631aeecc0928ff2b14265c
- https://git.kernel.org/stable/c/788dd28fd49610d6047cbb15dbf1186afffdfbaf
- https://git.kernel.org/stable/c/815a8d2feb5615ae7f0b5befd206af0b0160614c
- https://git.kernel.org/stable/c/87a1f93986aa1500b85aeff16b0b71c29ea116ea
- https://git.kernel.org/stable/c/89810e2d80281d42f855fac813786758ee16e323
- https://git.kernel.org/stable/c/b85ee287bfe52c6b2d9b41758b5e0d08679d5b39
- https://git.kernel.org/stable/c/f49faa4a64f8ac0e38983e606075b25dfcfc9ad4
- https://git.kernel.org/stable/c/f8b16d5764ee1e78c1ef333017ad383ffe76fcdc