Deadlock in Linux kernel - CVE-2026-80659
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock caused by recursive mutex acquisition in the vub300 mmc host driver when handling a command response timeout and resetting the USB device. A local user can trigger a command timeout that leads to a recursive acquisition of cmd_mutex to cause a denial of service.
The issue occurs because the reset path re-enters vub300_pre_reset() while the worker thread still holds cmd_mutex.
Affected software
How to mitigate CVE-2026-80659
External References
- https://git.kernel.org/stable/c/2e6b9a394206c76dd417c991312f349435ef35e6
- https://git.kernel.org/stable/c/7ee7a77ec2f446109ab52cc80ace7acc22ab6211
- https://git.kernel.org/stable/c/8344611477c9241f45f20981990780fc5f0996f8
- https://git.kernel.org/stable/c/8672b8bdbd2063b3fcbd75f729e4706fcdad2257
- https://git.kernel.org/stable/c/9f5e04235a0b59e6e30af9f45511addf2604d757
- https://git.kernel.org/stable/c/bf9848a22a8e50d39d5e8d871581f0a8110f16b3
- https://git.kernel.org/stable/c/c2e1d33929565fa14c48d8a5a45edc3ebfc941b2
- https://git.kernel.org/stable/c/ee5fb641c4ccac8406c668d3e947eb20ce44f233