Description
In the Linux kernel, the following vulnerability has been resolved:

serial: amba-pl011: keep console clock enabled for atomic writes

pl011_console_write_atomic() runs from nbcon atomic context, where
sleeping is not allowed. It calls clk_enable(), which takes the common-clk
enable_lock. Under PREEMPT_RT that is a sleeping lock:
clk_enable_lock() first tries spin_trylock_irqsave(), but on contention
falls back to spin_lock_irqsave(). Therefore, an atomic-context printk on
an RT kernel with a clk-backed pl011 can trip:

BUG: sleeping function called from invalid context at spinlock_rt.c:48
__might_resched from rt_spin_lock
rt_spin_lock from clk_enable_lock
clk_enable_lock from clk_enable
clk_enable from pl011_console_write_atomic
... from vprintk_emit

This was found and reproduced on PREEMPT_RT. Arm32 and arm64 DT SoCs are
affected; arm64 SBSA/ACPI has no clk, so clk_enable(NULL) short-circuits
before the lock. In addition, write_atomic() may be invoked from NMI
context and is documented to avoid locking. Removing clk_enable() from
the callback also avoids a potentially unsafe NMI acquisition of the
common-clock enable_lock.

An nbcon atomic-capable console must be printable from any context, so
the clock cannot be gated between writes. Enable the clock while the
console is available for output: use clk_prepare_enable() in
pl011_console_setup(), release it via clk_disable_unprepare() in the
console .exit() callback, and drop the per-write clk_enable()/clk_disable()
pairs from write_atomic() and write_thread().

When printk suspends consoles, drop the reference after
uart_suspend_port() stops console access and restore it before
uart_resume_port() -- but only if suspend actually marked the port
suspended (a wake-capable tty stays running and must keep its clock), and
keep it when console_suspend_enabled is false so no_console_suspend works.

The active power cost of keeping the clock enabled is platform-dependent:
none where the UART clock is a fixed always-on oscillator, real where it
is a gateable clock branch, which then cannot be gated (nor possibly can
its parent clocks) while the console is available for output. When serial
core actually suspends the port, the reference is released so the clock
provider can gate the clock tree.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

In arm32 and arm64 Linux kernels that employ the AMBA PL011 UART console, the driver invoked clk_enable() while in a non‑preemptible atomic context during atomic printk calls or NMI write_atomic() operations. The common‑clock enable lock can sleep in PREEMPT_RT builds, and when a sleeping routine is called from an atomic context a kernel BUG is triggered, causing a kernel panic and rendering the system unusable. The flaw does not provide a direct attacker control path; its effect is limited to a local fault condition that results in denial of service.

Affected Systems

The vulnerability affects all ARM 32‑bit and ARM 64‑bit System‑on‑Chip platforms that use the PL011 UART console driver in the Linux kernel. Any kernel build that mixes the PL011 console with a reclaimable clock source—commonly found in many embedded and IoT SoCs—falls under the impact scope.

Risk and Exploitability

The EPSS value is less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating a very low likelihood of observed exploitation. An attacker would need local kernel execution or the ability to trigger atomic printk or NMI context writes to the console. The issue is primarily a robustness bug that can be triggered by normal system activity, but it does not provide a vector for code execution or privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 04:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the upstream Linux kernel patch that moves the clock enable/disable logic out of per‑write callbacks into the console setup and exit paths; the patch is available in the referenced Git commit logs.
  • If upgrading is not immediately possible, apply the patch manually to the driver source in the current kernel tree and sync the console initialization to use clk_prepare_enable() and clk_disable_unprepare() instead of per‑write clk_enable()/clk_disable().
  • For systems that cannot apply the patch, disable the PL011 console from being used in atomic contexts (e.g., disable early printk or switch to a non‑sleep‑able console), or disable PREEMPT_RT to avoid the sleeping lock path.

Generated by OpenCVE AI on September 19, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-573

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: keep console clock enabled for atomic writes pl011_console_write_atomic() runs from nbcon atomic context, where sleeping is not allowed. It calls clk_enable(), which takes the common-clk enable_lock. Under PREEMPT_RT that is a sleeping lock: clk_enable_lock() first tries spin_trylock_irqsave(), but on contention falls back to spin_lock_irqsave(). Therefore, an atomic-context printk on an RT kernel with a clk-backed pl011 can trip: BUG: sleeping function called from invalid context at spinlock_rt.c:48 __might_resched from rt_spin_lock rt_spin_lock from clk_enable_lock clk_enable_lock from clk_enable clk_enable from pl011_console_write_atomic ... from vprintk_emit This was found and reproduced on PREEMPT_RT. Arm32 and arm64 DT SoCs are affected; arm64 SBSA/ACPI has no clk, so clk_enable(NULL) short-circuits before the lock. In addition, write_atomic() may be invoked from NMI context and is documented to avoid locking. Removing clk_enable() from the callback also avoids a potentially unsafe NMI acquisition of the common-clock enable_lock. An nbcon atomic-capable console must be printable from any context, so the clock cannot be gated between writes. Enable the clock while the console is available for output: use clk_prepare_enable() in pl011_console_setup(), release it via clk_disable_unprepare() in the console .exit() callback, and drop the per-write clk_enable()/clk_disable() pairs from write_atomic() and write_thread(). When printk suspends consoles, drop the reference after uart_suspend_port() stops console access and restore it before uart_resume_port() -- but only if suspend actually marked the port suspended (a wake-capable tty stays running and must keep its clock), and keep it when console_suspend_enabled is false so no_console_suspend works. The active power cost of keeping the clock enabled is platform-dependent: none where the UART clock is a fixed always-on oscillator, real where it is a gateable clock branch, which then cannot be gated (nor possibly can its parent clocks) while the console is available for output. When serial core actually suspends the port, the reference is released so the clock provider can gate the clock tree.
Title serial: amba-pl011: keep console clock enabled for atomic writes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:50.331Z

Reserved: 2026-09-11T19:38:34.804Z

Link: CVE-2026-90338

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:32.393

Modified: 2026-09-17T17:17:32.393

Link: CVE-2026-90338

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:15:14Z

Weaknesses
  • CWE-573

    Improper Following of Specification by Caller