Description
In the Linux kernel, the following vulnerability has been resolved:

virtio: rtc: time out alarm requests

RTC class operations run with rtc_device.ops_lock held. The virtio RTC
alarm requests currently wait without a timeout for the device to return
their requestq buffers.

On surprise removal, virtio-pci marks the virtqueues broken before
unregistering the virtio device. If an alarm request is waiting when the
device stops responding, viortc_remove() blocks in viortc_class_stop()
while trying to acquire ops_lock. The request cannot complete and device
removal hangs until the waiting task is signalled.

Use the same 60-second timeout as clock read requests for alarm reads,
alarm programming, and alarm interrupt enable requests. The existing
message reference counting keeps a timed-out request alive until a late
response or device teardown.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs when virtio‑RTC alarm requests wait indefinitely for a buffer return, because the driver holds ops_lock while blocking. The missing timeout causes the removal routine to deadlock on ops_lock, which can result in a stuck kernel thread. This behavior is inferred to produce a denial‑of‑service condition, as the hanging thread can stall system operations.

Affected Systems

This flaw affects the virtio‑RTC driver implementation in the Linux kernel. Any distribution or system running a Linux kernel that includes the unpatched virtio‑RTC code is at risk; no specific version range is listed, so all kernels prior to the patch that still use this module are potentially vulnerable.

Risk and Exploitability

The EPSS score is under 1 % and the vulnerability is not listed in CISA KEV, indicating a low current exploitation probability. The likely attack vector requires privileged or virtual‑environment control to force a virtio device to be removed or break. The post‑patch fix introduces a 60‑second timeout to prevent indefinite blocking, reducing the impact considerably if the patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 03:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the 60‑second timeout for virtio‑RTC alarm requests.
  • If a kernel upgrade cannot be performed immediately, disable or remove virtio‑RTC devices from the virtual environment to eliminate the hang condition.
  • Apply any available backport or patch that implements the timeout logic in the virtio‑RTC driver.

Generated by OpenCVE AI on September 20, 2026 at 03:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-666

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: virtio: rtc: time out alarm requests RTC class operations run with rtc_device.ops_lock held. The virtio RTC alarm requests currently wait without a timeout for the device to return their requestq buffers. On surprise removal, virtio-pci marks the virtqueues broken before unregistering the virtio device. If an alarm request is waiting when the device stops responding, viortc_remove() blocks in viortc_class_stop() while trying to acquire ops_lock. The request cannot complete and device removal hangs until the waiting task is signalled. Use the same 60-second timeout as clock read requests for alarm reads, alarm programming, and alarm interrupt enable requests. The existing message reference counting keeps a timed-out request alive until a late response or device teardown.
Title virtio: rtc: time out alarm requests
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:29.219Z

Reserved: 2026-09-11T19:38:34.788Z

Link: CVE-2026-90127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:05.080

Modified: 2026-09-17T17:17:05.080

Link: CVE-2026-90127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:15:08Z

Weaknesses
  • CWE-666

    Operation on Resource in Wrong Phase of Lifetime