CVE-2026-64429CWE-667

CVE-2026-64429

Medium · published July 25, 2026

CVSS v3.1
5.5
EPSS
0%
Percentile
0.7
In the wild
Unconfirmed
What it is

In the Linux kernel, the following vulnerability has been resolved:

gpio: eic-sprd: use raw_spinlock_t in the irq startup path

sprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller

state through sprd_eic_update(), which takes sprd_eic->lock with

spin_lock_irqsave(). The callback can be reached from irq_startup()

while setting up a requested IRQ. That path is not sleepable, but on

PREEMPT_RT a regular spinlock_t becomes a sleeping lock.

This issue was found by our static analysis tool and then manually

reviewed against the current tree.

The grounded PoC kept the request_threaded_irq() -> __setup_irq() ->

irq_startup() -> sprd_eic_irq_unmask() -> sprd_eic_update() carrier and

used the original spin_lock_irqsave(&sprd_eic->lock) edge. Lockdep

BUG: sleeping function called from invalid context

hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]

sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]

sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]

sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]

__setup_irq.constprop.0+0xd/0x30 [vuln_msv]

Convert the Spreadtrum EIC controller lock to raw_spinlock_t. The

locked section only serializes MMIO register updates and does not contain

sleepable operations, so keeping it non-sleeping is appropriate for the

irqchip callbacks.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00095 · 0.7th percentile
Weakness
CWE-667 · Improper Locking
Published
2026-07-25T14:17Z
Affected products (7)
ProductVersionsFixed in
linux/linux_kernel≥ 4.17, < 5.10.2615.10.261
linux/linux_kernel≥ 5.11, < 5.15.2125.15.212
linux/linux_kernel≥ 5.16, < 6.1.1786.1.178
linux/linux_kernel≥ 6.2, < 6.6.1456.6.145
linux/linux_kernel≥ 6.7, < 6.12.966.12.96
linux/linux_kernel≥ 6.13, < 6.18.396.18.39
linux/linux_kernel≥ 6.19, < 7.1.47.1.4
References (8)
EPSS history
Timeline
  • 25 JUL 08:51Z
    gpio: eic-sprd: use raw_spinlock_t in the irq startup path
    cvelistv5