CVE-2026-89946
In the Linux kernel, the following vulnerability has been resolved:
ASoC: cs35l33: drain threaded IRQ before runtime suspend
cs35l33_runtime_suspend() currently switches the codec into regcache_cache_only(true) and powers it down without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l33_irq_thread() can still run after suspend has closed off live register access.
A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked. If the threaded handler runs in that window, it reads volatile INT_STATUS_1/2 after cache_only has been enabled, ignores the regmap_read() failures, and can still drive the AMP_SHORT_RLS, CAL_ERR_RLS, OTE_RLS, and OTW_RLS release paths.
Leer descripción completaMostrar menos
Use disable_irq() before entering cache_only/power-off so any in-flight threaded handler is drained and no new IRQ thread can run during the suspended state. Re-enable the IRQ only after runtime_resume() has restored live register access with regcache_sync(). Since probe only warns if devm_request_threaded_irq() fails, track whether the IRQ was actually installed before disabling or re-enabling it.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5b5311427e54d9c0d07178ee42df68ba44c2d5ca
- https://git.kernel.org/stable/c/614c2616ea677abfbed917a92bdc5141efff3536
- https://git.kernel.org/stable/c/6ae98918240585eb2ad32b097c4810f4e2dabe88
- https://git.kernel.org/stable/c/6e369bc46663b4bfce3d5f8b8ed08e71ecea13a2
- https://git.kernel.org/stable/c/84cf6acd01a1ec8f30276578a039216327af782e
- https://git.kernel.org/stable/c/a04722542c76ce861031384480825afded8cc4f4
- https://git.kernel.org/stable/c/d07799302721d381aef834fac8a11d196894eccb
- https://git.kernel.org/stable/c/e074c12c428c633e079154301207a6079a208583
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89946",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "d07799302721d381aef834fac8a11d196894eccb",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "5b5311427e54d9c0d07178ee42df68ba44c2d5ca",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "a04722542c76ce861031384480825afded8cc4f4",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "614c2616ea677abfbed917a92bdc5141efff3536",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "6ae98918240585eb2ad32b097c4810f4e2dabe88",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "6e369bc46663b4bfce3d5f8b8ed08e71ecea13a2",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "84cf6acd01a1ec8f30276578a039216327af782e",
"versionType": "git"
},
{
"status": "affected",
"version": "3333cb7187b9c8d28f7a6405bbe9cec7a10efdc8",
"lessThan": "e074c12c428c633e079154301207a6079a208583",
"versionType": "git"
}
],
"programFiles": [
"sound/soc/codecs/cs35l33.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.8"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.8",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.51",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.5",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/soc/codecs/cs35l33.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-16T11:17:04.547",
"references": [
{
"url": "https://git.kernel.org/stable/c/5b5311427e54d9c0d07178ee42df68ba44c2d5ca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/614c2616ea677abfbed917a92bdc5141efff3536",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6ae98918240585eb2ad32b097c4810f4e2dabe88",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6e369bc46663b4bfce3d5f8b8ed08e71ecea13a2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/84cf6acd01a1ec8f30276578a039216327af782e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a04722542c76ce861031384480825afded8cc4f4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d07799302721d381aef834fac8a11d196894eccb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e074c12c428c633e079154301207a6079a208583",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: cs35l33: drain threaded IRQ before runtime suspend\n\ncs35l33_runtime_suspend() currently switches the codec into\nregcache_cache_only(true) and powers it down without first quiescing the\nthreaded IRQ registered by devm_request_threaded_irq(). That leaves a\nwindow where cs35l33_irq_thread() can still run after suspend has closed\noff live register access.\n\nA running system can reach this during runtime PM while the driver still\nhas critical fault IRQs unmasked. If the threaded handler runs in that\nwindow, it reads volatile INT_STATUS_1/2 after cache_only has been\nenabled, ignores the regmap_read() failures, and can still drive the\nAMP_SHORT_RLS, CAL_ERR_RLS, OTE_RLS, and OTW_RLS release paths.\n\nUse disable_irq() before entering cache_only/power-off so any in-flight\nthreaded handler is drained and no new IRQ thread can run during the\nsuspended state. Re-enable the IRQ only after runtime_resume() has\nrestored live register access with regcache_sync(). Since probe only\nwarns if devm_request_threaded_irq() fails, track whether the IRQ was\nactually installed before disabling or re-enabling it."
}
],
"lastModified": "2026-09-16T11:17:04.547",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}