Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: cs35l34: drain threaded IRQ before runtime suspend

cs35l34_runtime_suspend() currently switches the codec into
regcache_cache_only(true), asserts reset low, and powers the device off
without first quiescing the threaded IRQ registered by
devm_request_threaded_irq(). That leaves a window where
cs35l34_irq_thread() can still run after suspend has removed live
hardware access.

A running system can reach this during runtime PM while the driver still
has critical fault IRQs unmasked. If the threaded handler runs in that
window, it reads volatile INT_STATUS_1..4 after cache_only has been
enabled, ignores the regmap_read() failures, and can still execute the
PROT_RELEASE_CTL release sequence or the BST fault power-down writes.

Use disable_irq() before entering cache_only/reset-low/power-off so any
in-flight threaded handler is drained and no new IRQ thread can run
while the device is suspended. Re-enable the IRQ only after
runtime_resume() has restored live register access with regcache_sync().
Since probe only logs request_threaded_irq() failures and keeps going,
track whether the IRQ was actually installed before disabling or
re-enabling it.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race condition during runtime suspend that may result in incorrect device power‑down operations and system instability
Action: Immediate Patch
AI Analysis

Impact

The cs35l34 audio codec driver fails to drain its threaded interrupt request before entering runtime suspend. As a result, the interrupt handler can still execute after the device has been powered down and register access has been disabled. The handler reads volatile registers and may trigger firmware power‑down or release sequences, potentially corrupting the device state. This flaw is a race condition that could lead to unintended device behavior or system crashes.

Affected Systems

The vulnerability affects Linux kernel drivers implementing the Cirrus Logic CS35L34 codec. All kernel versions that include the cs35l34 driver without the patch are impacted; the flaw is specific to the ASoC subsystem in the Linux kernel.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires local privileged access to the kernel to exploit effectively and occurs during the runtime power‑management cycle. The CVSS score is not provided, but the presence of a race condition that can cause device corruption or crash warrants attention from system administrators.

Generated by OpenCVE AI on September 18, 2026 at 08:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the cs35l34 runtime suspend IRQ draining patch.
  • Disable runtime suspend for the cs35l34 device to eliminate the race window.
  • If an immediate kernel upgrade is not feasible, consider disabling the cs35l34 driver or avoiding usage of the codec until a patched kernel is available.

Generated by OpenCVE AI on September 18, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
CWE-416

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: cs35l34: drain threaded IRQ before runtime suspend cs35l34_runtime_suspend() currently switches the codec into regcache_cache_only(true), asserts reset low, and powers the device off without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l34_irq_thread() can still run after suspend has removed live hardware access. A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked. If the threaded handler runs in that window, it reads volatile INT_STATUS_1..4 after cache_only has been enabled, ignores the regmap_read() failures, and can still execute the PROT_RELEASE_CTL release sequence or the BST fault power-down writes. Use disable_irq() before entering cache_only/reset-low/power-off so any in-flight threaded handler is drained and no new IRQ thread can run while the device is suspended. Re-enable the IRQ only after runtime_resume() has restored live register access with regcache_sync(). Since probe only logs request_threaded_irq() failures and keeps going, track whether the IRQ was actually installed before disabling or re-enabling it.
Title ASoC: cs35l34: drain threaded IRQ before runtime suspend
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:31.951Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:04.383

Modified: 2026-09-16T11:17:04.383

Link: CVE-2026-89945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free