Description
In the Linux kernel, the following vulnerability has been resolved:

parisc: eisa: Fix infinite loop when parsing invalid IRQ value

When an invalid value is passed via the "eisa_irq_edge=" kernel
command line parameter (e.g. "eisa_irq_edge=16,5"), eisa_irq_setup()
prints an error message and continues without advancing the current
position. As a result the same invalid value is parsed again and
again, causing an infinite loop while the kernel boots.

Advance to the next comma-separated entry, or stop parsing when there
is no next entry, before continuing so that the remaining entries are
processed normally.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (system hang during boot)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability causes the kernel to enter an infinite loop when it encounters an invalid value supplied via the eisa_irq_edge command‑line parameter. The eisa_irq_setup() function prints an error but does not advance its parsing position, so the same bad value is repeatedly parsed, preventing the boot sequence from progressing. The result is a denial of service because the machine fails to boot and remains stuck.

Affected Systems

Linux kernel versions on the parisc architecture that support the eisa subsystem are affected. Any kernel build that includes the eisa infrastructure is vulnerable when an invalid eisa_irq_edge value is passed. No specific version range was identified.

Risk and Exploitability

The CVSS score is not disclosed, but the EPSS score is reported as less than 1 %, and the vulnerability is not listed in CISA KEV, indicating a low likelihood of widespread exploitation. The likely attack vector is local or requires the ability to modify kernel boot arguments – for example through a physical console, a compromised bootloader, or embedded firmware that injects malformed eisa_irq_edge values. Successful exploitation would only halt the boot process, resulting in a system‑wide denial of service without compromising data.

Generated by OpenCVE AI on September 18, 2026 at 07:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the fix committed to the Linux kernel repository
  • Remove or correct any eisa_irq_edge parameter in the boot configuration, ensuring all values are valid
  • Verify that the boot loader or firmware does not inject malformed eisa_irq_edge values when booting

Generated by OpenCVE AI on September 18, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: parisc: eisa: Fix infinite loop when parsing invalid IRQ value When an invalid value is passed via the "eisa_irq_edge=" kernel command line parameter (e.g. "eisa_irq_edge=16,5"), eisa_irq_setup() prints an error message and continues without advancing the current position. As a result the same invalid value is parsed again and again, causing an infinite loop while the kernel boots. Advance to the next comma-separated entry, or stop parsing when there is no next entry, before continuing so that the remaining entries are processed normally.
Title parisc: eisa: Fix infinite loop when parsing invalid IRQ value
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T09:29:20.218Z

Reserved: 2026-09-11T19:38:34.778Z

Link: CVE-2026-89964

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:06.907

Modified: 2026-09-17T10:17:05.227

Link: CVE-2026-89964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition