Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: cs35l33: drain threaded IRQ before runtime suspend

cs35l33_runtime_suspend() currently switches the codec into
regcache_cache_only(true) and powers it down without first quiescing the
threaded IRQ registered by devm_request_threaded_irq(). That leaves a
window where cs35l33_irq_thread() can still run after suspend has closed
off live register access.

A running system can reach this during runtime PM while the driver still
has critical fault IRQs unmasked. If the threaded handler runs in that
window, it reads volatile INT_STATUS_1/2 after cache_only has been
enabled, ignores the regmap_read() failures, and can still drive the
AMP_SHORT_RLS, CAL_ERR_RLS, OTE_RLS, and OTW_RLS release paths.

Use disable_irq() before entering cache_only/power-off so any in-flight
threaded handler is drained and no new IRQ thread can run during the
suspended state. Re-enable the IRQ only after runtime_resume() has
restored live register access with regcache_sync(). Since probe only
warns if devm_request_threaded_irq() fails, track whether the IRQ was
actually installed before disabling or re-enabling it.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential driver faults or system instability due to uncontrolled IRQ handling during suspend, which may lead to a denial of service
Action: Patch Now
AI Analysis

Impact

The cs35l33 ASoC driver in the Linux kernel allows a race condition between runtime suspend operations and an interrupt handler. During runtime PM the driver powers the codec down and enables regcache_cache_only, but it does not drain the threaded IRQ that is still registered. If the handler runs in the narrow window after cache_only is activated, it continues to read volatile status registers and attempts to drive release paths on the codec after power has been removed. This unchecked access can cause the driver to execute invalid hardware commands, potentially corrupting internal state or triggering a crash. The weakness can lead to loss of audio functionality or, in worst case, system instability and denial of service.

Affected Systems

The flaw exists in the Linux kernel in the ALSA System on Chip (ASoC) stack, specifically the cs35l33 codec driver. Any Linux system that uses the cs35l33 audio codec and enables runtime PM for the driver is affected. The issue is present in kernel versions before the fix; the precise version range is not enumerated in the data, so all affected kernels containing the unpatched driver should be examined. The vendor is Linux (kernel team).

Risk and Exploitability

This is a local code execution or denial of service risk that requires privileged access to the running system because it involves manipulating kernel driver behavior. The EPSS score is noted as <1%, indicating a very low but non‑zero probability of exploitation at the time of analysis. The vulnerability is not included in the CISA KEV catalog, reflecting limited known exploitation activity. The flaw is a classic race condition (CWE‑362) and could be triggered by an attacker capable of forcing the system into runtime suspend while the codec driver remains active and still has unmasked interrupts. However, because it relies on timing and the driver state, it is moderately difficult to exploit reliably.

Generated by OpenCVE AI on September 18, 2026 at 04:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that disables the IRQ before entering regcache_cache_only and re‑enables it only after regcache_sync during runtime_resume.
  • Verify that the driver has actually installed the threaded IRQ before disabling it in the probe function; update the driver code to track this state.
  • Update the system to a kernel version that contains the fix; if an immediate kernel update is not possible, disable runtime PM for the cs35l33 driver or prevent the driver from powering the codec down during suspend (e.g., via kernel boot parameters that force the codec to stay powered).

Generated by OpenCVE AI on September 18, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: cs35l33: drain threaded IRQ before runtime suspend cs35l33_runtime_suspend() currently switches the codec into regcache_cache_only(true) and powers it down without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l33_irq_thread() can still run after suspend has closed off live register access. A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked. If the threaded handler runs in that window, it reads volatile INT_STATUS_1/2 after cache_only has been enabled, ignores the regmap_read() failures, and can still drive the AMP_SHORT_RLS, CAL_ERR_RLS, OTE_RLS, and OTW_RLS release paths. Use disable_irq() before entering cache_only/power-off so any in-flight threaded handler is drained and no new IRQ thread can run during the suspended state. Re-enable the IRQ only after runtime_resume() has restored live register access with regcache_sync(). Since probe only warns if devm_request_threaded_irq() fails, track whether the IRQ was actually installed before disabling or re-enabling it.
Title ASoC: cs35l33: drain threaded IRQ before runtime suspend
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:32:32.675Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89946

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:04.547

Modified: 2026-09-16T11:17:04.547

Link: CVE-2026-89946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:12:44Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')