CVE-2026-46041
In the Linux kernel, the following vulnerability has been resolved:
greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()
hdlc_append() calls usleep_range() to wait for circular buffer space, but it is called with tx_producer_lock (a spinlock) held via hdlc_tx_frames() -> hdlc_append_tx_frame()/hdlc_append_tx_u8()/etc. Sleeping while holding a spinlock is illegal and can trigger "BUG: scheduling while atomic".
Fix this by moving the buffer-space wait out of hdlc_append() and into hdlc_tx_frames(), before the spinlock is acquired. The new flow:
1. Pre-calculate the worst-case encoded frame length. 2. Wait (with sleep) outside the lock until enough space is available, kicking the TX consumer work to drain the buffer. 3.
Leer descripción completaMostrar menos
Acquire the spinlock, re-verify space, and write the entire frame atomically.
This ensures that sleeping only happens without any lock held, and that frames are either fully enqueued or not written at all.
This bug is found by CodeQL static analysis tool (interprocedural sleep-in-atomic query) and my code review.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-46041",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "ec558bbfea671ac020a6dc6be8bf8f0ee556cce0",
"lessThan": "9f2b87bcdfed55145acbf932dc12f2c057145cad",
"versionType": "git"
},
{
"status": "affected",
"version": "ec558bbfea671ac020a6dc6be8bf8f0ee556cce0",
"lessThan": "b2801647c203a38e013802e9e9616b5bfac64968",
"versionType": "git"
},
{
"status": "affected",
"version": "ec558bbfea671ac020a6dc6be8bf8f0ee556cce0",
"lessThan": "51667fe2d9294d66e0228b9f51d1f01b6680a641",
"versionType": "git"
},
{
"status": "affected",
"version": "ec558bbfea671ac020a6dc6be8bf8f0ee556cce0",
"lessThan": "6b526dca0966f2370835765019a54319b78fca8d",
"versionType": "git"
}
],
"programFiles": [
"drivers/greybus/gb-beagleplay.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.86",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.27",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.4",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/greybus/gb-beagleplay.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-27T14:17:23.520",
"references": [
{
"url": "https://git.kernel.org/stable/c/51667fe2d9294d66e0228b9f51d1f01b6680a641",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b526dca0966f2370835765019a54319b78fca8d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f2b87bcdfed55145acbf932dc12f2c057145cad",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b2801647c203a38e013802e9e9616b5bfac64968",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngreybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()\n\nhdlc_append() calls usleep_range() to wait for circular buffer space,\nbut it is called with tx_producer_lock (a spinlock) held via\nhdlc_tx_frames() -> hdlc_append_tx_frame()/hdlc_append_tx_u8()/etc.\nSleeping while holding a spinlock is illegal and can trigger\n\"BUG: scheduling while atomic\".\n\nFix this by moving the buffer-space wait out of hdlc_append() and into\nhdlc_tx_frames(), before the spinlock is acquired. The new flow:\n\n 1. Pre-calculate the worst-case encoded frame length.\n 2. Wait (with sleep) outside the lock until enough space is available,\n kicking the TX consumer work to drain the buffer.\n 3. Acquire the spinlock, re-verify space, and write the entire frame\n atomically.\n\nThis ensures that sleeping only happens without any lock held, and\nthat frames are either fully enqueued or not written at all.\n\nThis bug is found by CodeQL static analysis tool (interprocedural\nsleep-in-atomic query) and my code review."
}
],
"lastModified": "2026-06-17T10:52:57.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55DA1C62-9991-451E-B8A8-E0004E00F789",
"versionEndExcluding": "6.12.86",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A10AC84F-C058-47D5-85B4-E6E51A613B74",
"versionEndExcluding": "6.18.27",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CDB78D6D-22C3-4154-B0D0-94AF1CE5C2E3",
"versionEndExcluding": "7.0.4",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}