Deadlock in Linux kernel - CVE-2026-80660
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a deadlock in the occ hwmon sysfs device handling in drivers/hwmon/occ/common.c when unregistering sysfs-backed devices during concurrent sysfs callbacks. A local user can trigger concurrent sysfs access and device shutdown activity to cause a denial of service.
The issue involves circular locking between the OCC mutex and sysfs callback draining during device deactivation or shutdown.
Affected software
How to mitigate CVE-2026-80660
External References
- https://git.kernel.org/stable/c/2092952f22a7da98e76e84139ae202b1fc7ba899
- https://git.kernel.org/stable/c/2a4c80ff3571498ec6a916273304b6650026b1b0
- https://git.kernel.org/stable/c/7ee43ec8e6774774abbe9dc3027225e01bc964a5
- https://git.kernel.org/stable/c/e31408734332b8cc611342cdaaab6ba492180156
- https://git.kernel.org/stable/c/e7fd81e9fb1fe476d2131fec66c1138457810ed4
- https://git.kernel.org/stable/c/f0aad157576da199c146c1bb266442befa7912ca