In the Linux kernel, the following vulnerability has been resolved: net: au1000: move free_irq...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
net: au1000: move free_irq out of the close-time spinlocked section
au1000_close() calls free_irq() while aup->lock is still held with spin_lock_irqsave(). free_irq() can sleep because it takes the IRQ descriptor request mutex, so it does not belong inside the close-time spinlocked section.
This was found by our static analysis tool and then confirmed by manual review of the in-tree au1000_close() .ndo_stop path. The reviewed path keeps aup->lock held across the MAC reset, queue stop and free_irq(dev->irq, dev).
A directed runtime validation kept that ndo_stop carrier and the same free_irq(dev->irq, dev) operation under the driver lock. Lockdep reported "BUG: sleeping function called from invalid context" and "Invalid wait context" while free_irq() was taking desc->request_mutex, with au1000_close() and free_irq() on the stack.
Drop aup->lock before freeing the IRQ. The protected close-time work still stops the device and queue before IRQ teardown, but the sleepable IRQ core path now runs outside the spinlocked section.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-93815
- https://git.kernel.org/stable/c/4536667fba8ddbaff2f2a135080ae6aabf737b5e
- https://git.kernel.org/stable/c/f48763beab4eea41fc480c9702ec6eebe8d75e4f
- https://git.kernel.org/stable/c/fc2233f1ab2a1ca562869bca6987d7477671388c
- https://git.kernel.org/stable/c/26fd652915123a690f19d62b253b545a53f3cd51
- https://git.kernel.org/stable/c/d514b08ed61fdffe23604fd3e9e53c07cbe5ac3e
- https://git.kernel.org/stable/c/e1b5a13249975fec3cf654efa84f57118db2da2c
- https://git.kernel.org/stable/c/f86bca5b7857b85bfa8afdb4fa895d7c0a3f7ebc
- https://github.com/advisories/GHSA-xvh7-3cp2-m6qq