CVE-2026-64429
Received Received - Intake

Race Condition in Linux Kernel GPIO EIC Controller

Vulnerability report for CVE-2026-64429, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-07-25

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: gpio: eic-sprd: use raw_spinlock_t in the irq startup path sprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller state through sprd_eic_update(), which takes sprd_eic->lock with spin_lock_irqsave(). The callback can be reached from irq_startup() while setting up a requested IRQ. That path is not sleepable, but on PREEMPT_RT a regular spinlock_t becomes a sleeping lock. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the request_threaded_irq() -> __setup_irq() -> irq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and used the original spin_lock_irqsave(&sprd_eic->lock) edge. Lockdep BUG: sleeping function called from invalid context hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv] sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv] sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv] sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv] __setup_irq.constprop.0+0xd/0x30 [vuln_msv] Convert the Spreadtrum EIC controller lock to raw_spinlock_t. The locked section only serializes MMIO register updates and does not contain sleepable operations, so keeping it non-sleeping is appropriate for the irqchip callbacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-07-25
Generated
2026-07-25
AI Q&A
2026-07-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sprd sprd_eic *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Linux kernel's GPIO controller for Spreadtrum devices. It involves a locking issue where a regular spinlock is used in an interrupt startup path that may sleep under PREEMPT_RT. This can cause a 'sleeping function called from invalid context' bug when enabling GPIO interrupts.

Detection Guidance

This vulnerability is specific to the Linux kernel's GPIO EIC driver for Spreadtrum platforms. Detection requires checking the kernel version and the presence of the affected driver. Use commands like 'uname -a' to check kernel version and 'lsmod | grep sprd_eic' to see if the vulnerable module is loaded.

Impact Analysis

This vulnerability could cause system instability or crashes on Linux systems using Spreadtrum GPIO controllers with PREEMPT_RT enabled. It may lead to kernel panics or unexpected behavior during interrupt handling.

Mitigation Strategies

Update your Linux kernel to a version that includes the fix for this vulnerability. The patch converts the spinlock to a raw_spinlock_t in the GPIO EIC driver. Check your distribution's security advisories for kernel updates addressing this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64429. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart