CVE-2026-93098
In the Linux kernel, the following vulnerability has been resolved:
rpmsg: glink: fix deadlock in endpoint destroy during driver detach
During driver detach, the device core holds the device mutex throughout the driver's remove callback chain. When the rpmsg endpoint is destroyed as part of that teardown, the GLINK endpoint destroy implementation attempts to unregister the underlying rpmsg device. That unregistration calls device_del(), which tries to re-acquire the same device mutex already held higher up the stack, causing rmmod to hang indefinitely.
The deadlock manifests with the following call chain:
Leer descripción completaMostrar menos
The rpmsg device unregistration inside endpoint destroy is redundant. In both contexts where endpoint destruction is triggered:
Remove the redundant unregistration to fix the deadlock.
Detalles técnicos trazas, registros y código del informe original
[<0>] device_del+0x44/0x414 <- tries to acquire same mutex [<0>] device_unregister+0x18/0x34 [<0>] rpmsg_unregister_device+0x28/0x4c [<0>] qcom_glink_remove_rpmsg_device+0x70/0xc0 [<0>] qcom_glink_destroy_ept+0x58/0xbc [<0>] rpmsg_dev_remove+0x50/0x60 [<0>] device_remove+0x4c/0x80 [<0>] device_release_driver_internal+0x1cc/0x228 <- acquires device mutex [<0>] driver_detach+0x4c/0x98 [<0>] bus_remove_driver+0x6c/0xbc [<0>] driver_unregister+0x30/0x60 [<0>] unregister_rpmsg_driver+0x10/0x1c [<0>] fastrpc_exit+0x28/0x38 [fastrpc] [<0>] __arm64_sys_delete_module+0x1b8/0x294 [<0>] invoke_syscall+0x48/0x10c [<0>] el0_svc_common.constprop.0+0xc0/0xe0 [<0>] do_el0_svc+0x1c/0x28 [<0>] el0_svc+0x34/0x108 [<0>] el0t_64_sync_handler+0xa0/0xe4 [<0>] el0t_64_sync+0x198/0x19c - Driver detach path: the driver core already tears down the rpmsg device. - Channel close path: the rpmsg device is already unregistered before endpoint destruction is reached.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/48f55b90f0d713e477e26b85d7327d9592d016f9
- https://git.kernel.org/stable/c/5a5a48e788e02fd8a8eb7188ce440572d6c12418
- https://git.kernel.org/stable/c/73092c2292aa65515671e54abbcda2166d3827ed
- https://git.kernel.org/stable/c/8597f669a5268e0dcf243e2b2d6ca00370117057
- https://git.kernel.org/stable/c/bbc236357876d35a624030e5c50eedbc380be98e
- https://git.kernel.org/stable/c/cbcdf96e1c87bc07055d04264018ded1f3bafffb
- https://git.kernel.org/stable/c/e559626bee8a6632aafc08eedcdb4bf26ca245c5
- https://git.kernel.org/stable/c/ecad679e2b92c419cc22cc8f257cd457d5192647
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93098",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "93b6b9e4acff4794e7426d3ad64ef14e3b3e8919",
"lessThan": "73092c2292aa65515671e54abbcda2166d3827ed",
"versionType": "git"
},
{
"status": "affected",
"version": "24fd02c3a4798de7dc94b55d36a1685fe6cdaf69",
"lessThan": "bbc236357876d35a624030e5c50eedbc380be98e",
"versionType": "git"
},
{
"status": "affected",
"version": "32fe8cdf541863239b81c80b8b04112d6e8792cf",
"lessThan": "8597f669a5268e0dcf243e2b2d6ca00370117057",
"versionType": "git"
},
{
"status": "affected",
"version": "c6210714347f72bae8e7142dc0a7f99923c466e7",
"lessThan": "48f55b90f0d713e477e26b85d7327d9592d016f9",
"versionType": "git"
},
{
"status": "affected",
"version": "fcab5c2672f8dac3d77013dbe047b2441f4141f5",
"lessThan": "cbcdf96e1c87bc07055d04264018ded1f3bafffb",
"versionType": "git"
},
{
"status": "affected",
"version": "f80e4e91b010ee7d6c52f24d069975ac955ac6b2",
"lessThan": "ecad679e2b92c419cc22cc8f257cd457d5192647",
"versionType": "git"
},
{
"status": "affected",
"version": "a53e356df548f6b0e82529ef3cc6070f42622189",
"lessThan": "e559626bee8a6632aafc08eedcdb4bf26ca245c5",
"versionType": "git"
},
{
"status": "affected",
"version": "a53e356df548f6b0e82529ef3cc6070f42622189",
"lessThan": "5a5a48e788e02fd8a8eb7188ce440572d6c12418",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.248",
"lessThan": "5.10.270",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.198",
"lessThan": "5.15.221",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.160",
"lessThan": "6.1.188",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.120",
"lessThan": "6.6.157",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.64",
"lessThan": "6.12.110",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.3",
"lessThan": "6.18.52",
"versionType": "semver"
}
],
"programFiles": [
"drivers/rpmsg/qcom_glink_native.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/rpmsg/qcom_glink_native.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:03.953",
"references": [
{
"url": "https://git.kernel.org/stable/c/48f55b90f0d713e477e26b85d7327d9592d016f9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5a5a48e788e02fd8a8eb7188ce440572d6c12418",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/73092c2292aa65515671e54abbcda2166d3827ed",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8597f669a5268e0dcf243e2b2d6ca00370117057",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bbc236357876d35a624030e5c50eedbc380be98e",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cbcdf96e1c87bc07055d04264018ded1f3bafffb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e559626bee8a6632aafc08eedcdb4bf26ca245c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ecad679e2b92c419cc22cc8f257cd457d5192647",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: glink: fix deadlock in endpoint destroy during driver detach\n\nDuring driver detach, the device core holds the device mutex throughout\nthe driver's remove callback chain. When the rpmsg endpoint is\ndestroyed as part of that teardown, the GLINK endpoint destroy\nimplementation attempts to unregister the underlying rpmsg device.\nThat unregistration calls device_del(), which tries to re-acquire the\nsame device mutex already held higher up the stack, causing rmmod to\nhang indefinitely.\n\nThe deadlock manifests with the following call chain:\n\n[<0>] device_del+0x44/0x414 <- tries to acquire same mutex\n[<0>] device_unregister+0x18/0x34\n[<0>] rpmsg_unregister_device+0x28/0x4c\n[<0>] qcom_glink_remove_rpmsg_device+0x70/0xc0\n[<0>] qcom_glink_destroy_ept+0x58/0xbc\n[<0>] rpmsg_dev_remove+0x50/0x60\n[<0>] device_remove+0x4c/0x80\n[<0>] device_release_driver_internal+0x1cc/0x228 <- acquires device mutex\n[<0>] driver_detach+0x4c/0x98\n[<0>] bus_remove_driver+0x6c/0xbc\n[<0>] driver_unregister+0x30/0x60\n[<0>] unregister_rpmsg_driver+0x10/0x1c\n[<0>] fastrpc_exit+0x28/0x38 [fastrpc]\n[<0>] __arm64_sys_delete_module+0x1b8/0x294\n[<0>] invoke_syscall+0x48/0x10c\n[<0>] el0_svc_common.constprop.0+0xc0/0xe0\n[<0>] do_el0_svc+0x1c/0x28\n[<0>] el0_svc+0x34/0x108\n[<0>] el0t_64_sync_handler+0xa0/0xe4\n[<0>] el0t_64_sync+0x198/0x19c\n\nThe rpmsg device unregistration inside endpoint destroy is redundant.\nIn both contexts where endpoint destruction is triggered:\n\n- Driver detach path: the driver core already tears down the rpmsg\n device.\n\n- Channel close path: the rpmsg device is already unregistered before\n endpoint destruction is reached.\n\nRemove the redundant unregistration to fix the deadlock."
}
],
"lastModified": "2026-09-17T17:18:03.953",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}