CVE-2026-64428
Received Received - Intake

Race Condition in Linux Kernel GPIO SCH Driver

Vulnerability report for CVE-2026-64428, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-07-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: gpio: sch: use raw_spinlock_t in the irq startup path sch_irq_unmask() enables the GPIO IRQ and then updates the controller state through sch_irq_mask_unmask(), which takes sch->lock with spin_lock_irqsave(). The callback can be reached from irq_startup() while setting up a requested IRQ. That path is not sleepable, but on PREEMPT_RT a regular spinlock_t becomes a sleeping lock. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the request_threaded_irq() -> __setup_irq() -> irq_startup() -> sch_irq_unmask() -> sch_irq_mask_unmask() carrier and used the original spin_lock_irqsave(&sch->lock) edge. Lockdep reported: BUG: sleeping function called from invalid context hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv] sch_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv] sch_irq_mask_unmask.constprop.0+0x31/0x70 [vuln_msv] __setup_irq.constprop.0+0xd/0x30 [vuln_msv] Convert the SCH controller lock to raw_spinlock_t. The same lock is also used by the GPIO direction and value callbacks, but those critical sections only update MMIO-backed GPIO registers and do not contain sleepable operations. Keeping this register lock non-sleeping is therefore appropriate for the irqchip callbacks and does not change the GPIO-side locking contract.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-07-25
Generated
2026-07-25
AI Q&A
2026-07-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a race condition in the GPIO interrupt handling for the SCH controller. The issue occurs when enabling an IRQ during startup, where a regular spinlock is used in a non-sleepable context. On PREEMPT_RT systems, this spinlock becomes a sleeping lock, causing a kernel bug where a sleeping function is called from invalid context.

Detection Guidance

This vulnerability is specific to the Linux kernel's GPIO subsystem and may not have direct network detection methods. Check kernel logs for lockdep warnings or BUG messages related to GPIO IRQ handling. Commands like dmesg | grep -i 'lockdep\|BUG\|sch_irq' may help identify issues.

Impact Analysis

This vulnerability can cause system instability or crashes on Linux systems using the SCH GPIO controller with PREEMPT_RT enabled. It may lead to kernel panics or unexpected behavior during IRQ setup, potentially disrupting hardware functionality.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for CVE-2026-64428. The patch converts the SCH controller lock to raw_spinlock_t to prevent sleeping in IRQ contexts. Monitor kernel updates from your distribution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64428. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart