Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 13 min 126 bronnen 3 kritiek 1 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-64238

MEDIUM · 5.5 CVSS Gepubliceerd: CWE-667

Beschrijving NL

In de Linux kernel is de volgende kwetsbaarheid verholpen:

gpio: shared: fix deadlock on shared proxy's parent removal

Commit 710abda58055 ("gpio: shared: call gpio_chip:: of_xlate () if set")
gebruikte de mutex ingebed in struct gpio_shared_entry om de
offsetveld dat nu kan worden gewijzigd na toewijzing. Het kritieke
sectie is echter te breed en introduceerde een mogelijke impasse op de
verwijdering van de ouder van de gedeelde GPIO-proxy. Maak het kritieke gedeelte korter - bescherm de offset alleen wanneer het
wordt gelezen. Terwijl je bezig bent: vermeld het feit dat het toegangsslot nu ook wordt gebruikt om
beschermen tegen gelijktijdige toegang tot het offsetveld in de
documentatie.

Origineel (Engels) tonen

In the Linux kernel, the following vulnerability has been resolved:

gpio: shared: fix deadlock on shared proxy's parent removal

Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set")
used the mutex embedded in struct gpio_shared_entry to protect the
offset field which now can be modified after assignment. The critical
section however is too wide and introduced a potential deadlock on the
removal of the shared GPIO proxy's parent.

Make the critical section shorter - only protect the offset when it's
being read.

While at it: mention the fact that the entry lock is now also used to
protect against concurrent access to the offset field in the structure's
documentation.

Vendors

Linux

Affected products

Linux Kernel

References