Description
In the Linux kernel, the following vulnerability has been resolved:

m68k: nfcon: Do not call console_is_registered() in nfcon_device()

Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list
synchronization") show_cons_active() calls the .device() method under
the console_list_lock, but console_is_registered() tries to acquire
console_list_lock as well, causing a deadlock. It should not be
necessary to check console_is_registered() here since the function
should not be called in the fist place when the console is not
registered.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, a deadlock occurs in the nfcon console driver on m68k architectures when nfcon_device() calls console_is_registered() while holding console_list_lock. The erroneous call attempts to acquire the same lock again, causing the kernel to stall. An attacker who can trigger this path can force the entire system into an unavailable state. The weakness is an instance of improper synchronization leading to deadlock.

Affected Systems

The vulnerability affects m68k kernels that include the nfcon console module prior to the fix commit 7c2af0f634f1. All distributions using these kernel versions are at risk; newer releases that removed the console_is_registered() check are not affected.

Risk and Exploitability

The deadlock yields a high‑impact denial of service, but exploitation requires a local or privileged attacker who can invoke nfcon_device(). The EPSS score is less than 1%, indicating a very low likelihood of exploitation, and the issue is not listed in the CISA KEV database. The expected attack vector is local kernel tampering or code injection that reaches the console path.

Generated by OpenCVE AI on September 20, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commit 7c2af0f634f1 or later, which removes the problematic console_is_registered() call.
  • If an immediate kernel upgrade is not possible, disable the nfcon console driver or avoid using console devices on the m68k platform until a patch is applied.
  • As a temporary measure, manually patch the kernel source to remove the console_is_registered() call from nfcon_device(), then recompile and install the kernel.

Generated by OpenCVE AI on September 20, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: m68k: nfcon: Do not call console_is_registered() in nfcon_device() Since 7c2af0f634f1 ("tty: tty_io: use console_list_lock for list synchronization") show_cons_active() calls the .device() method under the console_list_lock, but console_is_registered() tries to acquire console_list_lock as well, causing a deadlock. It should not be necessary to check console_is_registered() here since the function should not be called in the fist place when the console is not registered.
Title m68k: nfcon: Do not call console_is_registered() in nfcon_device()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:49.735Z

Reserved: 2026-09-11T19:38:34.790Z

Link: CVE-2026-90158

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:08.963

Modified: 2026-09-17T17:17:08.963

Link: CVE-2026-90158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:13Z

Weaknesses