« Volver al listado

CVE-2026-80999

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO

rtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from the probe path, which may sleep and is not timing-critical. When the reset GPIO is provided by a sleeping controller such as an I2C I/O expander, gpiod_set_value() warns:

Switch both helpers to gpiod_set_value_cansleep() so such a reset GPIO can be used without triggering the warning.

The reset GPIO has been driven with the non-sleeping gpiod_set_value() since the driver was added in v4.19.

Leer descripción completaMostrar menos

The call has since been refactored across several files - from realtek-smi.c / realtek-mdio.c into the common rtl83xx.c module and then into the rtl83xx_reset_assert() and rtl83xx_reset_deassert() helpers (both in v6.9). This patch therefore applies as-is only to kernels that carry those helpers (v6.9+); older stable kernels need the same gpiod_set_value_cansleep() conversion at the corresponding open-coded call sites.

Detalles técnicos trazas, registros y código del informe original
  WARNING: drivers/gpio/gpiolib.c:4030 at gpiod_set_value+0x44/0x80, CPU#1: kworker/u16:4/61
  Hardware name: B&O MAP CA33 Rev f (UNKNOWN) (DT)
  Workqueue: events_unbound deferred_probe_work_func
  pc : gpiod_set_value+0x44/0x80
  lr : rtl83xx_probe+0x1d8/0x3a0
  Call trace:
   gpiod_set_value+0x44/0x80 (P)
   rtl83xx_probe+0x1d8/0x3a0
   realtek_mdio_probe+0x24/0xa0
   mdio_probe+0x38/0x78
   really_probe+0xc4/0x3e0
   __driver_probe_device+0x15c/0x1b8
   driver_probe_device+0xb4/0x120
   __device_attach_driver+0xb8/0x1a0
   bus_for_each_drv+0x88/0xf0
   __device_attach+0xa0/0x1d8
   device_initial_probe+0x54/0x68
   bus_probe_device+0x38/0xa0
   deferred_probe_work_func+0xb8/0x120
   process_one_work+0x184/0x4e8
   worker_thread+0x188/0x308
   kthread+0x130/0x150
   ret_from_fork+0x10/0x20

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80999",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d8652956cf37c5caa8c19e0b99ce5ca235c6d5de",
              "lessThan": "c32cf5292a0dd70c4afc138b4dc45743a190cd5a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d8652956cf37c5caa8c19e0b99ce5ca235c6d5de",
              "lessThan": "f71087e7c63aa3e99bf65d7ddf91eb4fd3545778",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d8652956cf37c5caa8c19e0b99ce5ca235c6d5de",
              "lessThan": "1610a8c2b93e815e3dc8643a2a69ab1c37975a6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d8652956cf37c5caa8c19e0b99ce5ca235c6d5de",
              "lessThan": "fb58b6a696b30bcbfbe0cfc0a91b19c816a955fc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/net/dsa/realtek/rtl83xx.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/net/dsa/realtek/rtl83xx.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:07.433",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1610a8c2b93e815e3dc8643a2a69ab1c37975a6a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c32cf5292a0dd70c4afc138b4dc45743a190cd5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f71087e7c63aa3e99bf65d7ddf91eb4fd3545778",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fb58b6a696b30bcbfbe0cfc0a91b19c816a955fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO\n\nrtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from\nthe probe path, which may sleep and is not timing-critical.  When the\nreset GPIO is provided by a sleeping controller such as an I2C I/O\nexpander, gpiod_set_value() warns:\n\n  WARNING: drivers/gpio/gpiolib.c:4030 at gpiod_set_value+0x44/0x80, CPU#1: kworker/u16:4/61\n  Hardware name: B&O MAP CA33 Rev f (UNKNOWN) (DT)\n  Workqueue: events_unbound deferred_probe_work_func\n  pc : gpiod_set_value+0x44/0x80\n  lr : rtl83xx_probe+0x1d8/0x3a0\n  Call trace:\n   gpiod_set_value+0x44/0x80 (P)\n   rtl83xx_probe+0x1d8/0x3a0\n   realtek_mdio_probe+0x24/0xa0\n   mdio_probe+0x38/0x78\n   really_probe+0xc4/0x3e0\n   __driver_probe_device+0x15c/0x1b8\n   driver_probe_device+0xb4/0x120\n   __device_attach_driver+0xb8/0x1a0\n   bus_for_each_drv+0x88/0xf0\n   __device_attach+0xa0/0x1d8\n   device_initial_probe+0x54/0x68\n   bus_probe_device+0x38/0xa0\n   deferred_probe_work_func+0xb8/0x120\n   process_one_work+0x184/0x4e8\n   worker_thread+0x188/0x308\n   kthread+0x130/0x150\n   ret_from_fork+0x10/0x20\n\nSwitch both helpers to gpiod_set_value_cansleep() so such a reset GPIO can\nbe used without triggering the warning.\n\nThe reset GPIO has been driven with the non-sleeping gpiod_set_value()\nsince the driver was added in v4.19.  The call has since been refactored\nacross several files - from realtek-smi.c / realtek-mdio.c into the common\nrtl83xx.c module and then into the rtl83xx_reset_assert() and\nrtl83xx_reset_deassert() helpers (both in v6.9).  This patch therefore\napplies as-is only to kernels that carry those helpers (v6.9+); older\nstable kernels need the same gpiod_set_value_cansleep() conversion at the\ncorresponding open-coded call sites."
    }
  ],
  "lastModified": "2026-09-11T20:19:07.433",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}