Description
In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcxhr: initialize mutexes before requesting threaded IRQ

pcxhr_probe() requests pcxhr_threaded_irq() before initializing
mgr->lock, even though the threaded handler takes that mutex.

Initialize the manager locks before request_threaded_irq() so an
early interrupt cannot run against uninitialized mutex state during
probe.
Published: 2026-09-11
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Undefined behavior during driver initialization, potentially leading to kernel instability
Action: Apply Patch
AI Analysis

Impact

The ALSA pcxhr driver in the Linux kernel requests a threaded interrupt before initializing its manager mutex. Because the threaded handler acquires this mutex, an interrupt that occurs during driver probe can run with the mutex in an uninitialized state. This race condition leads to undefined behavior during driver initialization.

Affected Systems

All Linux kernels that ship the unpatched pcxhr ALSA driver are affected. The kernel source indicates the fix without specifying a particular version range, implying that any kernel older than the patch contains the issue. Since the ALSA subsystem is present across mainstream distributions, a wide array of systems may be vulnerable.

Risk and Exploitability

The CVSS score of 8.4 denotes high severity. The EPSS score of <1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no public exploits are known. The most probable attack vector requires a local or privileged attacker to trigger an interrupt while the driver is probing, such as by manipulating a PCI device.

Generated by OpenCVE AI on September 21, 2026 at 02:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the pcxhr driver patch
  • If an upgrade is not possible, blacklist the pcxhr module to prevent it from loading during boot
  • If the driver must remain active, unload it after boot and avoid using it until the system is stable
  • Monitor system logs for messages indicating driver initialization failures or unexpected interrupts

Generated by OpenCVE AI on September 21, 2026 at 02:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-909
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ALSA: pcxhr: initialize mutexes before requesting threaded IRQ pcxhr_probe() requests pcxhr_threaded_irq() before initializing mgr->lock, even though the threaded handler takes that mutex. Initialize the manager locks before request_threaded_irq() so an early interrupt cannot run against uninitialized mutex state during probe.
Title ALSA: pcxhr: initialize mutexes before requesting threaded IRQ
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:13.926Z

Reserved: 2026-08-26T14:34:25.810Z

Link: CVE-2026-80967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:02.720

Modified: 2026-09-14T13:18:51.370

Link: CVE-2026-80967

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:31Z

Links: CVE-2026-80967 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:30:08Z

Weaknesses
  • CWE-909

    Missing Initialization of Resource