Improper locking in Linux kernel - CVE-2026-80562
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper lock type selection in the gpio-ml-ioh driver irq callbacks when invoking irq_set_type, irq_enable, or irq_disable while the IRQ descriptor lock is held in a non-sleepable context. A local user can trigger these callbacks to cause a denial of service.
The issue is specific to PREEMPT_RT kernels.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-80562
linux (Debian package) - update to 6.12.107-1