Description
In the Linux kernel, the following vulnerability has been resolved:

acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks

The CXL CPER work registration and unregistration helpers acquire
cxl_cper_work_lock and cxl_cper_prot_err_work_lock with a spinlock
guard(), which leaves local interrupts enabled. The corresponding post
paths (cxl_cper_post_event(), cxl_cper_post_prot_err()) execute in hard
IRQ context (they are called from the GHES error notification path) and
acquire the same locks with an irqsave guard().

If a CPU is holding one of these locks via a spinlock guard() when a GHES
interrupt arrives on the same CPU, the IRQ handler spins on the held lock
waiting for it to release, while the lock holder is preempted by the IRQ.
The result is a deadlock.

Convert both locks from spinlock_t to raw_spinlock_t and use guard() at
all call sites. On PREEMPT_RT kernels spinlock_t is backed by rt_mutex and
sleeping from hard IRQ context is not permitted; raw_spinlock_t is safe in
both contexts.

Add WARN_ONCE to both register functions to surface double-registration
bugs at runtime.

Restructure both unregister functions to clear the global work pointer
under the lock before calling cancel_work_sync(), closing the window
where a CPER interrupt could schedule work on a pointer about to be
freed. Add kfifo_reset() after cancel_work_sync() so stale entries
are not replayed on next module load.

Both kfifos are single-consumer: only one work_struct is registered at
a time, enforced by the WARN_ONCE guard in the register functions.
kfifo_reset() is safe outside the lock because cancel_work_sync() has
already quiesced the consumer, and no new consumer can register until
the current module exit completes and a fresh module init runs.

Remove the redundant cancel_work_sync() call from cxl_ras_exit() and
cxl_pci_driver_exit(). The CPER unregister functions now quiesce
the work internally.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel deadlock due to conflicting lock usage
Action: Patch
AI Analysis

Impact

In the Linux kernel’s ACPI/APEI/ghes module, the CXL CPER work registration helpers lock with a spinlock guard(), which leaves local interrupts enabled. When a GHES error interrupt occurs on the same CPU, the interrupt handler attempts to acquire the same lock with irqsave, causing the handler to spin while its preempted lock holder waits. This circular wait results in a deadlock that stalls the kernel, potentially rendering the system unresponsive. The flaw is a classic priority‑inversion deadlock identified as CWE‑833.

Affected Systems

All installations of the Linux kernel that compile the ACPI/APEI/ghes component with CXL CPER support and have not applied the commit converting the locks to raw_spinlock_t are affected. The vulnerability applies to every Linux kernel version built prior to the patched release, regardless of vendor distribution.

Risk and Exploitability

The CVSS score of 4.4 reflects low severity, and the EPSS score of less than 1% indicates that exploitation is unlikely. Because the deadlock requires a GHES interrupt, which is typically generated by a hardware fault or by privileged local firmware actions, the attack vector is local and non‑remote. The vulnerability is not listed in CISA’s KEV catalog. Overall, the risk to an attacker is low; the primary impact is a kernel stall rather than information disclosure or remote compromise.

Generated by OpenCVE AI on September 15, 2026 at 22:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that includes the commit converting cxl_cper_work_lock and cxl_cper_prot_err_work_lock to raw_spinlock_t and guarding all accesses.
  • If an upgrade is not possible, apply the upstream patch to change the lock types and guard functions, then rebuild and install the kernel module.
  • Verify that all lock acquisitions in the ACPI/APEI/ghes code path use raw_spinlock_t and that guard() is applied consistently during both normal and interrupt contexts.

Generated by OpenCVE AI on September 15, 2026 at 22:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-674

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-833
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-674

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks The CXL CPER work registration and unregistration helpers acquire cxl_cper_work_lock and cxl_cper_prot_err_work_lock with a spinlock guard(), which leaves local interrupts enabled. The corresponding post paths (cxl_cper_post_event(), cxl_cper_post_prot_err()) execute in hard IRQ context (they are called from the GHES error notification path) and acquire the same locks with an irqsave guard(). If a CPU is holding one of these locks via a spinlock guard() when a GHES interrupt arrives on the same CPU, the IRQ handler spins on the held lock waiting for it to release, while the lock holder is preempted by the IRQ. The result is a deadlock. Convert both locks from spinlock_t to raw_spinlock_t and use guard() at all call sites. On PREEMPT_RT kernels spinlock_t is backed by rt_mutex and sleeping from hard IRQ context is not permitted; raw_spinlock_t is safe in both contexts. Add WARN_ONCE to both register functions to surface double-registration bugs at runtime. Restructure both unregister functions to clear the global work pointer under the lock before calling cancel_work_sync(), closing the window where a CPER interrupt could schedule work on a pointer about to be freed. Add kfifo_reset() after cancel_work_sync() so stale entries are not replayed on next module load. Both kfifos are single-consumer: only one work_struct is registered at a time, enforced by the WARN_ONCE guard in the register functions. kfifo_reset() is safe outside the lock because cancel_work_sync() has already quiesced the consumer, and no new consumer can register until the current module exit completes and a fresh module init runs. Remove the redundant cancel_work_sync() call from cxl_ras_exit() and cxl_pci_driver_exit(). The CPER unregister functions now quiesce the work internally.
Title acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:32.569Z

Reserved: 2026-09-11T19:38:34.729Z

Link: CVE-2026-89589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:43.437

Modified: 2026-09-21T14:17:23.690

Link: CVE-2026-89589

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:53Z

Links: CVE-2026-89589 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:15:17Z

Weaknesses