« Volver al listado

CVE-2026-98094

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

staging: fbtft: make dirty_lock IRQ-safe

fbtft_mkdirty() can be reached from the fbcon rendering path while processing printk() in hardirq context. Meanwhile, dirty_lock is also taken by fbtft_deferred_io() in workqueue context with local interrupts enabled.

Lockdep reports a possible IRQ lock inversion involving dirty_lock and console_owner. A hardirq can interrupt a CPU holding dirty_lock and enter the console rendering path, which can attempt to acquire dirty_lock again.

The following lockdep report was observed on an RK3566 system with CONFIG_PROVE_LOCKING enabled:

Leer descripción completaMostrar menos

Use spin_lock_irqsave() for fbtft_mkdirty() and spin_lock_irq() for fbtft_deferred_io(). They only access the dirty line range, so the IRQ-off regions remain short.

Detalles técnicos trazas, registros y código del informe original
  WARNING: possible irq lock inversion dependency detected
  swapper/2/0 just changed the state of lock:
  (console_owner){-...}-{0:0}
  but this lock took another, HARDIRQ-unsafe lock in the past:
  (&par->dirty_lock){+.+.}-{2:2}

  CPU0                    CPU1
  ----                    ----
  lock(&par->dirty_lock);
                         local_irq_disable();
                         lock(console_owner);
                         lock(&par->dirty_lock);
  <Interrupt>
    lock(console_owner);

  *** DEADLOCK ***

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98094",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "0843298b159599ee7bc6d14800efdb4bc7349706",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "a323066337ed85c38decfc7f6bbf42f27605dff1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "f2451e18826eb6a33ea51419f39bdd2eb99fa1ea",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "10cc145b873670438d3b105133dffdae70822db6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "2a609e29efbba79f9abd68c4ec8a2bd7ecf291e7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "f0c869df2c33793c8828acaab3e4a5e0176f9f00",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "dcb48fde8003492256dee45815144aa5ed26ce7c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c296d5f9957c03994a699d6739c27d4581a9f6c7",
              "lessThan": "f576944a59f31bcffff121117ebf452c5dd162b7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/staging/fbtft/fbtft-core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/staging/fbtft/fbtft-core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:39.133",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0843298b159599ee7bc6d14800efdb4bc7349706",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/10cc145b873670438d3b105133dffdae70822db6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2a609e29efbba79f9abd68c4ec8a2bd7ecf291e7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a323066337ed85c38decfc7f6bbf42f27605dff1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dcb48fde8003492256dee45815144aa5ed26ce7c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0c869df2c33793c8828acaab3e4a5e0176f9f00",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f2451e18826eb6a33ea51419f39bdd2eb99fa1ea",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f576944a59f31bcffff121117ebf452c5dd162b7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: fbtft: make dirty_lock IRQ-safe\n\nfbtft_mkdirty() can be reached from the fbcon rendering path while\nprocessing printk() in hardirq context. Meanwhile, dirty_lock is also\ntaken by fbtft_deferred_io() in workqueue context with local interrupts\nenabled.\n\nLockdep reports a possible IRQ lock inversion involving dirty_lock and\nconsole_owner. A hardirq can interrupt a CPU holding dirty_lock and\nenter the console rendering path, which can attempt to acquire\ndirty_lock again.\n\nThe following lockdep report was observed on an RK3566 system with\nCONFIG_PROVE_LOCKING enabled:\n\n  WARNING: possible irq lock inversion dependency detected\n  swapper/2/0 just changed the state of lock:\n  (console_owner){-...}-{0:0}\n  but this lock took another, HARDIRQ-unsafe lock in the past:\n  (&par->dirty_lock){+.+.}-{2:2}\n\n  CPU0                    CPU1\n  ----                    ----\n  lock(&par->dirty_lock);\n                         local_irq_disable();\n                         lock(console_owner);\n                         lock(&par->dirty_lock);\n  <Interrupt>\n    lock(console_owner);\n\n  *** DEADLOCK ***\n\nUse spin_lock_irqsave() for fbtft_mkdirty() and spin_lock_irq() for\nfbtft_deferred_io(). They only access the dirty line range, so the\nIRQ-off regions remain short."
    }
  ],
  "lastModified": "2026-10-03T11:18:31.457",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}