« Volver al listado

CVE-2026-90127

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

virtio: rtc: time out alarm requests

RTC class operations run with rtc_device.ops_lock held. The virtio RTC alarm requests currently wait without a timeout for the device to return their requestq buffers.

On surprise removal, virtio-pci marks the virtqueues broken before unregistering the virtio device. If an alarm request is waiting when the device stops responding, viortc_remove() blocks in viortc_class_stop() while trying to acquire ops_lock. The request cannot complete and device removal hangs until the waiting task is signalled.

Leer descripción completaMostrar menos

Use the same 60-second timeout as clock read requests for alarm reads, alarm programming, and alarm interrupt enable requests. The existing message reference counting keeps a timed-out request alive until a late response or device teardown.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90127",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9d4f22fd563e0cd02e8448e84d057e7c0132a586",
              "lessThan": "28701b74c22d2a43ddf7aebb6378e60c18323865",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d4f22fd563e0cd02e8448e84d057e7c0132a586",
              "lessThan": "afbf69d1d691c06d093d7c3f17168ecb608c4977",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9d4f22fd563e0cd02e8448e84d057e7c0132a586",
              "lessThan": "68e00d9212929805b40dcb9166755610f4f4acee",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/virtio/virtio_rtc_driver.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/virtio/virtio_rtc_driver.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:05.080",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/28701b74c22d2a43ddf7aebb6378e60c18323865",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/68e00d9212929805b40dcb9166755610f4f4acee",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/afbf69d1d691c06d093d7c3f17168ecb608c4977",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio: rtc: time out alarm requests\n\nRTC class operations run with rtc_device.ops_lock held. The virtio RTC\nalarm requests currently wait without a timeout for the device to return\ntheir requestq buffers.\n\nOn surprise removal, virtio-pci marks the virtqueues broken before\nunregistering the virtio device. If an alarm request is waiting when the\ndevice stops responding, viortc_remove() blocks in viortc_class_stop()\nwhile trying to acquire ops_lock. The request cannot complete and device\nremoval hangs until the waiting task is signalled.\n\nUse the same 60-second timeout as clock read requests for alarm reads,\nalarm programming, and alarm interrupt enable requests. The existing\nmessage reference counting keeps a timed-out request alive until a late\nresponse or device teardown."
    }
  ],
  "lastModified": "2026-09-17T17:17:05.080",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}