Description
In the Linux kernel, the following vulnerability has been resolved:

arm64: hibernate: Restore DAIF state on error

Sashiko AI has reported that if swsusp_mte_save_tags() for some reason
fails we return from swsusp_arch_suspend() with DAIF being masked -
that is not what we'd expect. Restore the saved DAIF state before
returning from the error path.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service from persistent interrupt masking after a failed suspend operation
Action: Upgrade Kernel
AI Analysis

Impact

The Linux arm64 kernel has a path that handles errors from the sleep‑q suspend mechanism (swsusp). When swsusp_mte_save_tags() fails, the routine returns to swsusp_arch_suspend() with the DAIF register masked. The DAIF bits control the masking of interrupts; if they remain set, the processor will not process any interrupts until cleared. This flaw can cause the kernel to hang, resulting in loss of scheduled tasks, network service, or any interrupt‑driven activity. The vulnerability is an internal state‑management error and does not provide a remote exploitation route; however, a local or privileged user can trigger it by inducing a suspend failure or attempting to hibernate the system.

Affected Systems

All Linux kernels running on arm64 architecture are impacted if they include the buggy error path before the patch that restores the saved DAIF state. The CPE string reflects an overall Linux kernel, and no specific version range is supplied, meaning any arm64 kernel build that predates the fix is potentially vulnerable.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in CISA KEV, indicating a very low recent exploitation probability. The CVSS score is not provided. Because the flaw requires local or privileged code to trigger a suspend failure, the attack vector is local or privileged. Consequently, the risk to availability is limited to environments where the failed suspend path can be invoked, and no remotely exploitable payload exists.

Generated by OpenCVE AI on September 20, 2026 at 00:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the patch restoring the DAIF state before the error path (the relevant commit series is referenced in the advisory).
  • If a kernel upgrade is not immediately possible, disable suspend or hibernate functionality on the arm64 system, or configure the kernel to avoid using the swsusp path.
  • If a kernel upgrade is not possible and disabling suspend is impractical, apply the patch from the commit series cited in the advisory or rebuild the kernel with the updated code to restore proper DAIF state handling.

Generated by OpenCVE AI on September 20, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: arm64: hibernate: Restore DAIF state on error Sashiko AI has reported that if swsusp_mte_save_tags() for some reason fails we return from swsusp_arch_suspend() with DAIF being masked - that is not what we'd expect. Restore the saved DAIF state before returning from the error path.
Title arm64: hibernate: Restore DAIF state on error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:18.058Z

Reserved: 2026-09-11T19:38:34.798Z

Link: CVE-2026-90290

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:26.113

Modified: 2026-09-17T17:17:26.113

Link: CVE-2026-90290

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:00:13Z

Weaknesses