Description
In the Linux kernel, the following vulnerability has been resolved:

slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd

When the remoteproc starts in parallel with the NGD driver being probed,
or the remoteproc is already up when the PDR lookup is being registered,
or in the theoretical event that we get an interrupt from the hardware,
these callbacks will operate on uninitialized data. This result in
issues to boot the affected boards.

One such example can be seen in the following fault, where
qcom_slim_ngd_ssr_pdr_notify() schedules work on the NULL ngd_up_work.

[ 21.858578] ------------[ cut here ]------------
[ 21.858745] WARNING: kernel/workqueue.c:2338 at __queue_work+0x5e0/0x790, CPU#2: kworker/2:2/116
...
[ 21.859251] Call trace:
[ 21.859255] __queue_work+0x5e0/0x790 (P)
[ 21.859265] queue_work_on+0x6c/0xf0
[ 21.859273] qcom_slim_ngd_ssr_pdr_notify+0x110/0x150 [slim_qcom_ngd_ctrl]
[ 21.859304] qcom_slim_ngd_ssr_notify+0x24/0x40 [slim_qcom_ngd_ctrl]
[ 21.859318] notifier_call_chain+0xa4/0x230
[ 21.859329] srcu_notifier_call_chain+0x64/0xb8
[ 21.859338] ssr_notify_start+0x40/0x78 [qcom_common]
[ 21.859355] rproc_start+0x130/0x230
[ 21.859367] rproc_boot+0x3d4/0x518
...

Move the enablement of interrupts, and the registration of SSR and PDR
until after the NGD device has been registered.

This could be further refined by moving initialization to the control
driver probe and by removing the platform driver model from the picture.
Published: 2026-07-01
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in the Qualcomm SLIMBus NGD controller driver causes callbacks to be registered and invoked before the NGD device is fully initialized. When a remote‑processor starts or a hardware interrupt occurs concurrently with the driver probe, the driver may dereference a null pointer, leading to a kernel panic during boot. This flaw is a classic null reference error that can prevent the board from booting normally.

Affected Systems

Linux kernel builds that include the slimbus/qcom‑ngd‑ctrl module on Qualcomm platforms using the SLIMBus interconnect are affected. Any kernel version that has not integrated the upstream patch and still loads this module at startup is vulnerable. Systems that omit the module or run a patched kernel are not at risk.

Risk and Exploitability

The EPSS score of <1 % and the absence from CISA’s KEV catalog indicate a low likelihood of exploitation in the wild. Based on the description, it is inferred that exploitation would require an attacker with privileged access to the device, capable of manipulating the timing of remote‑processor initialization or triggering hardware interrupts during driver probe. Successful exploitation would cause a kernel panic, halting the system and preventing normal boot, resulting in a denial of service.

Generated by OpenCVE AI on August 3, 2026 at 06:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the upstream fix which defers interrupt enablement and SSR/PDR registration until after the NGD device has been registered.
  • If an upgrade is not immediately possible, disable or unload the slimbus/qcom‑ngd‑ctrl module at boot so its callbacks are not registered prematurely.
  • When the module must remain active, modify the boot sequence so that remote‑processor services start only after the SLIMBus NGD driver has fully initialized, ensuring callbacks operate on a valid device state.

Generated by OpenCVE AI on August 3, 2026 at 06:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4717-1 linux security update
Debian DLA Debian DLA DLA-4720-1 linux security update
Debian DLA Debian DLA DLA-4723-1 linux-6.1 security update
History

Fri, 24 Jul 2026 18:30:00 +0000


Sat, 04 Jul 2026 12:15:00 +0000


Thu, 02 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-489
CWE-665

Thu, 02 Jul 2026 00:15:00 +0000


Wed, 01 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-489
CWE-665

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remoteproc starts in parallel with the NGD driver being probed, or the remoteproc is already up when the PDR lookup is being registered, or in the theoretical event that we get an interrupt from the hardware, these callbacks will operate on uninitialized data. This result in issues to boot the affected boards. One such example can be seen in the following fault, where qcom_slim_ngd_ssr_pdr_notify() schedules work on the NULL ngd_up_work. [ 21.858578] ------------[ cut here ]------------ [ 21.858745] WARNING: kernel/workqueue.c:2338 at __queue_work+0x5e0/0x790, CPU#2: kworker/2:2/116 ... [ 21.859251] Call trace: [ 21.859255] __queue_work+0x5e0/0x790 (P) [ 21.859265] queue_work_on+0x6c/0xf0 [ 21.859273] qcom_slim_ngd_ssr_pdr_notify+0x110/0x150 [slim_qcom_ngd_ctrl] [ 21.859304] qcom_slim_ngd_ssr_notify+0x24/0x40 [slim_qcom_ngd_ctrl] [ 21.859318] notifier_call_chain+0xa4/0x230 [ 21.859329] srcu_notifier_call_chain+0x64/0xb8 [ 21.859338] ssr_notify_start+0x40/0x78 [qcom_common] [ 21.859355] rproc_start+0x130/0x230 [ 21.859367] rproc_boot+0x3d4/0x518 ... Move the enablement of interrupts, and the registration of SSR and PDR until after the NGD device has been registered. This could be further refined by moving initialization to the control driver probe and by removing the platform driver model from the picture.
Title slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-07-24T14:33:51.996Z

Reserved: 2026-06-09T07:44:35.398Z

Link: CVE-2026-53332

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2026-07-01T14:16:41.137

Modified: 2026-07-24T15:18:00.473

Link: CVE-2026-53332

cve-icon Redhat

Severity :

Publid Date: 2026-07-01T00:00:00Z

Links: CVE-2026-53332 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:15:04Z

Weaknesses