CVE-2026-89589
Received Received - Intake

Deadlock in Linux Kernel CXL CPER Work Lock Handling

Vulnerability report for CVE-2026-89589, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-21

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks The CXL CPER work registration and unregistration helpers acquire cxl_cper_work_lock and cxl_cper_prot_err_work_lock with a spinlock guard(), which leaves local interrupts enabled. The corresponding post paths (cxl_cper_post_event(), cxl_cper_post_prot_err()) execute in hard IRQ context (they are called from the GHES error notification path) and acquire the same locks with an irqsave guard(). If a CPU is holding one of these locks via a spinlock guard() when a GHES interrupt arrives on the same CPU, the IRQ handler spins on the held lock waiting for it to release, while the lock holder is preempted by the IRQ. The result is a deadlock. Convert both locks from spinlock_t to raw_spinlock_t and use guard() at all call sites. On PREEMPT_RT kernels spinlock_t is backed by rt_mutex and sleeping from hard IRQ context is not permitted; raw_spinlock_t is safe in both contexts. Add WARN_ONCE to both register functions to surface double-registration bugs at runtime. Restructure both unregister functions to clear the global work pointer under the lock before calling cancel_work_sync(), closing the window where a CPER interrupt could schedule work on a pointer about to be freed. Add kfifo_reset() after cancel_work_sync() so stale entries are not replayed on next module load. Both kfifos are single-consumer: only one work_struct is registered at a time, enforced by the WARN_ONCE guard in the register functions. kfifo_reset() is safe outside the lock because cancel_work_sync() has already quiesced the consumer, and no new consumer can register until the current module exit completes and a fresh module init runs. Remove the redundant cancel_work_sync() call from cxl_ras_exit() and cxl_pci_driver_exit(). The CPER unregister functions now quiesce the work internally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-21
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a deadlock issue in the Linux kernel related to CXL CPER (Component Firmware Error Record) error handling. The problem occurs when a CPU holds a lock while a GHES (Generic Hardware Error Source) interrupt arrives on the same CPU. The interrupt handler tries to acquire the same lock, causing a deadlock because the lock holder is preempted by the interrupt.

Detection Guidance

This vulnerability is specific to the Linux kernel's ACPI/APEI/ghes and CXL CPER components. Detection requires checking kernel logs for deadlock warnings or lock contention issues related to cxl_cper_work_lock or cxl_cper_prot_err_work_lock. No network-specific detection commands are applicable.

Impact Analysis

This vulnerability can cause system hangs or crashes if a deadlock occurs. It primarily affects systems using the Linux kernel with CXL (Compute Express Link) hardware and GHES error handling enabled. The impact is limited to specific hardware configurations and kernel versions.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA as it is a low-level kernel deadlock issue in the Linux CXL CPER error handling. Compliance impacts would only occur if the deadlock caused system unavailability or data corruption, which is not described in the provided context.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for CVE-2026-89589. The vulnerability is resolved by converting spinlock_t to raw_spinlock_t in the CXL CPER work locks. Check your distribution's security advisories for kernel updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89589. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart