← All Advisories

Linux Kernel au1000 Ethernet Driver Calls free_irq While Holding a Spinlock with Interrupts Disabled, Which Can Sleep and Deadlock on Platforms Without Threaded IRQs

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-93815

Key Details

CVECVE-2026-93815

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: au1000: move free_irq out of the close-time spinlocked section

au1000_close() calls free_irq() while aup->lock is still held with

spin_lock_irqsave(). free_irq() can sleep because it takes the IRQ

descriptor request mutex, so it does not belong inside the close-time

spinlocked section.

This was found by our static analysis tool and then confirmed by manual

review of the in-tree au1000_close() .ndo_stop path. The reviewed path

keeps aup->lock held across the MAC reset, queue stop and

free_irq(dev->irq, dev).

A directed runtime validation kept that ndo_stop carrier and the same

free_irq(dev->irq, dev) operation under the driver lock. Lockdep reported

"BUG: sleeping function called from invalid context" and "Invalid wait

context" while free_irq() was taking desc->request_mutex, with

au1000_close() and free_irq() on the stack.

Drop aup->lock before freeing the IRQ. The protected close-time work still

stops the device and queue before IRQ teardown, but the sleepable IRQ core

path now runs outside the spinlocked section. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-93815
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-93815