« Volver al listado

CVE-2026-90193

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding chan->lock. Under PREEMPT_RT, spin_lock_irqsave() is converted to an rt_spinlock (rtmutex-based), which tracks ownership and can sleep.

The callback chain triggered by mbox_chan_received_data() eventually reaches mailbox_clear_channel() -> mbox_send_message() -> add_to_rbuf(), which attempts to re-acquire the same chan->lock. Since rtmutex detects the re-entrant lock attempt by the same owner, the thread blocks waiting for a lock it already holds, causing a permanent deadlock.

Leer descripción completaMostrar menos

Fix by saving chan->cl locally and clearing the HW interrupt register inside the lock, then invoking mbox_chan_received_data() after releasing the lock. This preserves the mutual exclusion for chan->cl access while avoiding the lock re-entrancy that causes the PREEMPT_RT deadlock.

Detalles técnicos trazas, registros y código del informe original
This deadlock manifests as 'irq/N-apss_cpucp_mbox' stuck in D state
with the following call trace:
  rt_spin_lock -> mbox_send_message -> mailbox_clear_channel ->
  scmi_rx_callback -> mbox_chan_received_data [<- held chan->lock here]

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90193",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "0e2a9a03106cd5fa0dbc9047675e7645c55e2669",
              "lessThan": "aa482273f32117c3adeba9b1cc945e0b5d33722d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0e2a9a03106cd5fa0dbc9047675e7645c55e2669",
              "lessThan": "8b8de6400c86937ed57d680d06d716e167b381de",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0e2a9a03106cd5fa0dbc9047675e7645c55e2669",
              "lessThan": "e40b3edeaf25cd09e9c88edb1ef99373ca37593b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "0e2a9a03106cd5fa0dbc9047675e7645c55e2669",
              "lessThan": "3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/mailbox/qcom-cpucp-mbox.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/mailbox/qcom-cpucp-mbox.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:14.030",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8b8de6400c86937ed57d680d06d716e167b381de",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa482273f32117c3adeba9b1cc945e0b5d33722d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e40b3edeaf25cd09e9c88edb1ef99373ca37593b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler\n\nqcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding\nchan->lock. Under PREEMPT_RT, spin_lock_irqsave() is converted to an\nrt_spinlock (rtmutex-based), which tracks ownership and can sleep.\n\nThe callback chain triggered by mbox_chan_received_data() eventually\nreaches mailbox_clear_channel() -> mbox_send_message() -> add_to_rbuf(),\nwhich attempts to re-acquire the same chan->lock. Since rtmutex detects\nthe re-entrant lock attempt by the same owner, the thread blocks waiting\nfor a lock it already holds, causing a permanent deadlock.\n\nThis deadlock manifests as 'irq/N-apss_cpucp_mbox' stuck in D state\nwith the following call trace:\n  rt_spin_lock -> mbox_send_message -> mailbox_clear_channel ->\n  scmi_rx_callback -> mbox_chan_received_data [<- held chan->lock here]\n\nFix by saving chan->cl locally and clearing the HW interrupt register\ninside the lock, then invoking mbox_chan_received_data() after releasing\nthe lock. This preserves the mutual exclusion for chan->cl access while\navoiding the lock re-entrancy that causes the PREEMPT_RT deadlock."
    }
  ],
  "lastModified": "2026-09-17T17:17:14.030",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}