Description
In the Linux kernel, the following vulnerability has been resolved:

irqchip/renesas-rzg2l: Fix loss of interrupt

rzg2l_clear_irq_int() and rzg2l_clear_tint_int() perform a
read-modify-write on the ISCR/TSCR status registers to clear the bit
for the interrupt just handled. Since these registers are
write-0-to-clear per bit, this is racy:

If another interrupt's status bit gets set between the read and the write,
that bit is written back as 0 by the software-constructed value, clearing
an interrupt that hasn't been serviced yet and losing it.

This can be reproduced by triggering multiple interrupts at once, e.g.:

gpioset -c gpiochip0 355=0 353=0 328=0 352=0

Fix this by writing back only the bit being cleared, with all other bits
set to 1, instead of read-modify-writing the whole register. Since 1-bits
are left unchanged by hardware, concurrently-set status bits for other
interrupts are preserved.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Interrupt Loss and Service Disruption
Action: Immediate Patch
AI Analysis

Impact

In the Linux kernel, the rzg2l_clear_irq_int() and rzg2l_clear_tint_int() functions perform a read‑modify‑write to clear interrupt status bits, assuming the hardware clears bits when written with zero. Because this operation is not atomic, an interrupt that is set between the read and the write can be cleared inadvertently, resulting in lost interrupt events. The impact is the loss of pending interrupts, which can degrade real‑time performance or cause services relying on timely interrupt handling to miss events; it does not enable arbitrary code execution or direct data corruption.

Affected Systems

The flaw appears in the irqchip drivers for Renesas RZ‑G2L platforms in the Linux kernel, affecting all kernel releases prior to the commit that implements the write‑back‑with‑ones fix. All distributions shipping a kernel that contains the renesas‑rzg2l driver are potentially impacted; specific versions are not enumerated, so any kernel using this driver before the patch is included.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a very low probability of exploitation. The likely attack vector involves generating multiple simultaneous GPIO interrupts—such as by using the gpioset command—to force a race condition during interrupt handling. Successful exploitation requires local access to the affected device and relies on a precise timing window, so the risk is moderate for systems where interrupts are critical, but it does not currently provide remote code execution or broader system compromise.

Generated by OpenCVE AI on September 20, 2026 at 02:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that includes the commit which writes back only the clear bit for the rzg2l IRQ chip.
  • If an immediate kernel upgrade is not possible, disable or serialize the GPIO interrupts that can fire concurrently, or replace the renesas‑rzg2l driver with an alternative that handles status bits atomically.
  • Enable or review system logging for missed interrupt events and configure alerts so that administrators are notified of potential interrupt loss.

Generated by OpenCVE AI on September 20, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-727

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: irqchip/renesas-rzg2l: Fix loss of interrupt rzg2l_clear_irq_int() and rzg2l_clear_tint_int() perform a read-modify-write on the ISCR/TSCR status registers to clear the bit for the interrupt just handled. Since these registers are write-0-to-clear per bit, this is racy: If another interrupt's status bit gets set between the read and the write, that bit is written back as 0 by the software-constructed value, clearing an interrupt that hasn't been serviced yet and losing it. This can be reproduced by triggering multiple interrupts at once, e.g.: gpioset -c gpiochip0 355=0 353=0 328=0 352=0 Fix this by writing back only the bit being cleared, with all other bits set to 1, instead of read-modify-writing the whole register. Since 1-bits are left unchanged by hardware, concurrently-set status bits for other interrupts are preserved.
Title irqchip/renesas-rzg2l: Fix loss of interrupt
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:27.254Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.650

Modified: 2026-09-17T17:17:04.650

Link: CVE-2026-90124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses