CVE-2026-97909
In the Linux kernel, the following vulnerability has been resolved:
ASoC: sti: initialize IRQ lock before requesting IRQ
uni_reader_init() registers the shared IRQ before initializing reader->irq_lock. A pending interrupt can invoke the handler while the lock is still uninitialized.
Initialize the lock before registering the IRQ so the interrupt path always sees valid lock state.
CVSS
NVD hasn't assigned a CVSS score to this CVE (common since the April 2026 policy change).
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.21%
- Percentile among all scored CVEs: 10
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
References
- https://git.kernel.org/stable/c/04405aeef4f8d7bcac6dcb1947acafdb4420c2c3
- https://git.kernel.org/stable/c/181bb64a1333bbf3c369123d05614536f3ae7b7c
- https://git.kernel.org/stable/c/3a9552d18fc8174bab015bc941ede19452b184b3
- https://git.kernel.org/stable/c/45021eb56211431f0ef44001b7d12cce32d49261
- https://git.kernel.org/stable/c/9128265f0fc8031a71775d70786052e5631aac54
- https://git.kernel.org/stable/c/998ca92f69bc43499705016d02ffaf0663126d57
- https://git.kernel.org/stable/c/a42dd4dae4c9191caa017cf54cc40b6bb125be65
- https://git.kernel.org/stable/c/f1e7b74512164314d0550ec5b62e3d40b95b0986
Raw JSON (NVD)
Show
{
"id": "CVE-2026-97909",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "9128265f0fc8031a71775d70786052e5631aac54",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "181bb64a1333bbf3c369123d05614536f3ae7b7c",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "3a9552d18fc8174bab015bc941ede19452b184b3",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "45021eb56211431f0ef44001b7d12cce32d49261",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "f1e7b74512164314d0550ec5b62e3d40b95b0986",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "998ca92f69bc43499705016d02ffaf0663126d57",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "a42dd4dae4c9191caa017cf54cc40b6bb125be65",
"versionType": "git"
},
{
"status": "affected",
"version": "d05d862ead8eca5e7d4ccf82d39d9189579ee5b1",
"lessThan": "04405aeef4f8d7bcac6dcb1947acafdb4420c2c3",
"versionType": "git"
}
],
"programFiles": [
"sound/soc/sti/uniperif_reader.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/soc/sti/uniperif_reader.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:17.847",
"references": [
{
"url": "https://git.kernel.org/stable/c/04405aeef4f8d7bcac6dcb1947acafdb4420c2c3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/181bb64a1333bbf3c369123d05614536f3ae7b7c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3a9552d18fc8174bab015bc941ede19452b184b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/45021eb56211431f0ef44001b7d12cce32d49261",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9128265f0fc8031a71775d70786052e5631aac54",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/998ca92f69bc43499705016d02ffaf0663126d57",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a42dd4dae4c9191caa017cf54cc40b6bb125be65",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f1e7b74512164314d0550ec5b62e3d40b95b0986",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: sti: initialize IRQ lock before requesting IRQ\n\nuni_reader_init() registers the shared IRQ before initializing\nreader->irq_lock. A pending interrupt can invoke the handler while the\nlock is still uninitialized.\n\nInitialize the lock before registering the IRQ so the interrupt path\nalways sees valid lock state."
}
],
"lastModified": "2026-10-03T11:18:09.177",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}