Description
In the Linux kernel, the following vulnerability has been resolved:

net: sparx5: fix sleep in atomic context in MAC table access

sparx5_set_rx_mode() runs with netif_addr_lock_bh held and iterates
dev->mc via __dev_mc_sync(), which per address calls sparx5_mc_sync() /
sparx5_mc_unsync() -> sparx5_mact_learn() / sparx5_mact_forget(). These
take sparx5->lock, a mutex, and then poll the MAC access command
register with readx_poll_timeout(). A mutex may block, which is not
allowed from atomic context.

Convert the driver to the new .ndo_set_rx_mode_async callback introduced
in commit 3554b4345d85 ("net: introduce ndo_set_rx_mode_async and
netdev_rx_mode_work"). The async callback is invoked from process
context, so the mutex and sleeping completion poll can remain.

Observed with CONFIG_PROVE_LOCKING, CONFIG_DEBUG_SPINLOCK,
CONFIG_DEBUG_MUTEXES and CONFIG_DEBUG_ATOMIC_SLEEP enabled:

BUG: sleeping function called from invalid context at kernel/locking/mutex.c:591
in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 217, name: ip
preempt_count: 201, expected: 0
Call trace:
__might_resched+0x144/0x248
__might_sleep+0x48/0x7c
__mutex_lock+0x74/0x850
mutex_lock_nested+0x24/0x30
sparx5_mact_learn+0x78/0x100
sparx5_mc_sync+0x40/0x54
__hw_addr_sync_dev+0xc4/0x170
sparx5_set_rx_mode+0x4c/0x58
__dev_set_rx_mode+0x64/0xa4
__dev_open+0x1ec/0x26c
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash leading to denial of service
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel sparx5 network driver, a function that causes the kernel to sleep is invoked while a mutex is held inside an atomic context. Atomic contexts are prohibited from sleeping, so the kernel raises a BUG assertion, which can result in a kernel panic. The fault does not expose data, but it can cause system instability and an unplanned reboot. The defect is confined to the sparx5 driver and surfaces when network address multicast tables are synchronized through the ndo_set_rx_mode interface.

Affected Systems

The vulnerability affects all Linux kernel builds that include an unpatched sparx5 driver. The issue exists in any kernel version before the patch that introduces the ndo_set_rx_mode_async callback. As no specific versions are enumerated in the CNA data, all affected kernels are potentially at risk until they receive the fix.

Risk and Exploitability

The EPSS score for this flaw is below 1% and it is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. However, if an attacker can trigger the affected code path—such as by sending crafted multicast traffic—they could force a kernel panic and cause denial of service. The CVSS score is not provided, but the impact is level‑3 since it only produces a crash and not data compromise. The likely attack vector involves local or remote network traffic that triggers the driver’s address sync logic. The risk is therefore moderate, dominated by the potential for DoS rather than an exploitable security breach.

Generated by OpenCVE AI on September 20, 2026 at 04:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes commit 3554b4345d85, which implements the ndo_set_rx_mode_async callback and removes the blocking mutex from atomic context.
  • Re‑boot the system after applying the kernel update to ensure the kernel is running a stable, patched code base.
  • If a kernel upgrade is not immediately possible, verify that the sparx5 driver is disabled or replaced with an alternative network driver to avoid the buggy code path.
  • Monitor system logs for any occurrences of "sleeping function called from invalid context" and verify that the issue no longer appears after the patch.

Generated by OpenCVE AI on September 20, 2026 at 04:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-676
CWE-755

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: sparx5: fix sleep in atomic context in MAC table access sparx5_set_rx_mode() runs with netif_addr_lock_bh held and iterates dev->mc via __dev_mc_sync(), which per address calls sparx5_mc_sync() / sparx5_mc_unsync() -> sparx5_mact_learn() / sparx5_mact_forget(). These take sparx5->lock, a mutex, and then poll the MAC access command register with readx_poll_timeout(). A mutex may block, which is not allowed from atomic context. Convert the driver to the new .ndo_set_rx_mode_async callback introduced in commit 3554b4345d85 ("net: introduce ndo_set_rx_mode_async and netdev_rx_mode_work"). The async callback is invoked from process context, so the mutex and sleeping completion poll can remain. Observed with CONFIG_PROVE_LOCKING, CONFIG_DEBUG_SPINLOCK, CONFIG_DEBUG_MUTEXES and CONFIG_DEBUG_ATOMIC_SLEEP enabled: BUG: sleeping function called from invalid context at kernel/locking/mutex.c:591 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 217, name: ip preempt_count: 201, expected: 0 Call trace: __might_resched+0x144/0x248 __might_sleep+0x48/0x7c __mutex_lock+0x74/0x850 mutex_lock_nested+0x24/0x30 sparx5_mact_learn+0x78/0x100 sparx5_mc_sync+0x40/0x54 __hw_addr_sync_dev+0xc4/0x170 sparx5_set_rx_mode+0x4c/0x58 __dev_set_rx_mode+0x64/0xa4 __dev_open+0x1ec/0x26c
Title net: sparx5: fix sleep in atomic context in MAC table access
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:10.203Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90098

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.460

Modified: 2026-09-17T17:17:01.460

Link: CVE-2026-90098

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-676

    Use of Potentially Dangerous Function

  • CWE-755

    Improper Handling of Exceptional Conditions