Description
In the Linux kernel, the following vulnerability has been resolved:

media: qcom: iris: use disable_irq() during power-off

The IRQ is registered as a threaded IRQ.

Using disable_irq_nosync() in iris_vpu_power_off() does not wait
for an already queued threaded IRQ handler to complete before
returning.

As a result, a threaded IRQ handler may still run after the VPU has
been powered down and access hardware registers after power-off.

Replace disable_irq_nosync() with disable_irq() so the power-off path
waits for any in-flight threaded IRQ handler to complete before
returning.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential hardware register access after power‑off leading to instability or denial of service
Action: Patch Kernel
AI Analysis

Impact

In the Linux kernel the Qualcomm Iris VPU driver used the non‑synchronizing function disable_irq_nosync() during power‑off. Because the IRQ is threaded, the handler could still run after the function returned, allowing code to access VPU registers that had already been powered down. This race can cause undefined hardware behavior, crashes or denial of service. The weakness is a race condition that violates correct shutdown sequencing.

Affected Systems

Affected systems are Linux kernel builds that include the Qualcomm iris VPU driver. The change applies to the media subsystem and any kernel version where the iris driver registers a threaded IRQ. No specific kernel releases are listed, so all kernels that ship the legacy iris driver are potentially impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of public exploitation at present. The lack of a publicly disclosed CVSS score limits a formal severity assessment, but the code path described involves kernel privilege and hardware access, implying that an attacker with kernel‑level authority could potentially trigger the race condition. The risk of exploitation depends on whether the Iris VPU driver is loaded and active; if the driver is present, the unreconciled threaded IRQ handler could run after the power‑off path, potentially accessing powered‑down registers and causing instability or denial of service.

Generated by OpenCVE AI on September 18, 2026 at 08:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Replace the call to disable_irq_nosync() with disable_irq() in the iris_vpu_power_off() function, which ensures the kernel waits for any active threaded IRQ handler to finish before returning.
  • Rebuild and load the updated kernel or driver module to apply the fix.
  • If an immediate kernel update is unavailable, consider temporarily disabling the iris VPU driver or preventing power‑off triggers until the patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: media: qcom: iris: use disable_irq() during power-off The IRQ is registered as a threaded IRQ. Using disable_irq_nosync() in iris_vpu_power_off() does not wait for an already queued threaded IRQ handler to complete before returning. As a result, a threaded IRQ handler may still run after the VPU has been powered down and access hardware registers after power-off. Replace disable_irq_nosync() with disable_irq() so the power-off path waits for any in-flight threaded IRQ handler to complete before returning.
Title media: qcom: iris: use disable_irq() during power-off
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:38.572Z

Reserved: 2026-09-11T19:38:34.771Z

Link: CVE-2026-89869

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:55.050

Modified: 2026-09-16T11:16:55.050

Link: CVE-2026-89869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')