Deadlock in Linux kernel - CVE-2026-89589
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper locking in the CXL CPER work registration and unregistration helpers in drivers/acpi/apei/ghes.c when a GHES interrupt arrives while a CPU holds a CXL CPER work lock. A local privileged user can trigger the locking race to cause a denial of service.
The affected CXL CPER post paths execute in hard IRQ context.