Description
In the Linux kernel, the following vulnerability has been resolved:

s390/debug: Fix deadlock during unregister

Unregistering an s390dbf debug area while one of the associated debugfs
files is being written to can cause a deadlock:

$ echo >.../vmur/level $ rmmod vmur
===================================================
debugfs write
debugfs_file_get()
debug_unregister()
mutex_lock(debug_mutex)
debugfs_remove()
wait for debugfs_file_put()
debug_file_ops.write()
debug_input()
mutex_lock(debug_mutex) ==> DEADLOCK

Fix this by splitting debug_unregister() into an s390dbf and debugfs
part, and running only the s390dbf part with debug_mutex locked.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel deadlock)
Action: Immediate Patch
AI Analysis

Impact

An issue in the Linux kernel’s s390 debugging subsystem can cause a deadlock when an s390 database file area is unregistered while a user is writing to one of its debugfs files. The code path holding a global debug mutex leads to a cycle of lock acquisition and waiting that stalls the system. The fix splits the unregister routine, reducing mutex contention to only the s390dbf component. The vulnerability is notable because it can bring the kernel to a halt, resulting in a denial of service for all users on the affected system.

Affected Systems

The affected product is the Linux kernel. Any kernel version that contains the legacy s390/debug unregister implementation before the patch commits (all releases prior to the commits linked in the advisory) is susceptible. The patch has been applied in [commit a08b70ed2d1ec907353a72f15163b8e34ff4b2f8] and related commit refs. All users of the Linux kernel running on s390 hardware without these updates are impacted.

Risk and Exploitability

The vulnerability has no publicly known exploits and is listed as not in the CISA KEV catalog. Its EPSS score is less than 1%, indicating a very low probability of exploitation. Nevertheless, an attacker with local, privileged access could trigger the deadlock by interleaving a write to a debugfs file with a module unload or kernel module removal, leading to a system freeze. The impact is limited to denial of service, with no compromise of confidentiality or integrity.

Generated by OpenCVE AI on September 20, 2026 at 01:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the fix (apply the patch from commit a08b70ed2d1ec907353a72f15163b8e34ff4b2f8 or later).
  • Reboot into the patched kernel so the updated s390 debugging code is loaded.
  • If an immediate kernel update is unavailable, avoid unloading s390 debug modules while debugfs files are open, or temporarily block debugfs writes during module removal to prevent the deadlock.

Generated by OpenCVE AI on September 20, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-410

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister Unregistering an s390dbf debug area while one of the associated debugfs files is being written to can cause a deadlock: $ echo >.../vmur/level $ rmmod vmur =================================================== debugfs write debugfs_file_get() debug_unregister() mutex_lock(debug_mutex) debugfs_remove() wait for debugfs_file_put() debug_file_ops.write() debug_input() mutex_lock(debug_mutex) ==> DEADLOCK Fix this by splitting debug_unregister() into an s390dbf and debugfs part, and running only the s390dbf part with debug_mutex locked.
Title s390/debug: Fix deadlock during unregister
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:24.126Z

Reserved: 2026-09-11T19:38:34.793Z

Link: CVE-2026-90209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:16.060

Modified: 2026-09-17T17:17:16.060

Link: CVE-2026-90209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:30:16Z

Weaknesses
  • CWE-410

    Insufficient Resource Pool