Description
In the Linux kernel, the following vulnerability has been resolved:

leds: lp5860: Fix a potential double-unlock

In lp5860_device_init(), if lp5860_init_dt() fails, an already unlocked
mutex is unlocked another time.

Slightly rework how the lock is taken/released to avoid this potential
double unlock.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a flaw in the lp5860 LED driver where a failed initialization path causes an already unlocked mutex to be unlocked again. This double unlock can corrupt the internal state of the mutex. It is inferred that such corruption may trigger a kernel panic or other undefined behavior that would interrupt system availability.

Affected Systems

All Linux kernel deployments that include the lp5860 LED driver are potentially affected. The specific kernel versions are not enumerated in the provided sources; the bug exists in any kernel build that compiles this driver. Users running mainstream distributions that ship the default kernel, such as Ubuntu, Fedora, Debian, or RHEL, may be impacted if the driver is enabled.

Risk and Exploitability

The EPSS score is listed as < 1 %, and the vulnerability is not in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. It is inferred that an attacker would need to run code with kernel‑level privileges or manipulate the device tree during initialization to trigger the failure condition. Without such privileged access or a malicious device tree, the attack surface is quite narrow.

Generated by OpenCVE AI on September 19, 2026 at 09:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest version that incorporates the commit fixing the double‑unlock bug (see the referenced kernel commits).
  • If a kernel update cannot be performed immediately, disable the lp5860 LED driver or prevent its initialization code from executing to avoid the unlock sequence.
  • Configure monitoring or log collection to alert on kernel panics or oops events so that incidents can be detected and addressed promptly.

Generated by OpenCVE AI on September 19, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: leds: lp5860: Fix a potential double-unlock In lp5860_device_init(), if lp5860_init_dt() fails, an already unlocked mutex is unlocked another time. Slightly rework how the lock is taken/released to avoid this potential double unlock.
Title leds: lp5860: Fix a potential double-unlock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:01.897Z

Reserved: 2026-09-17T16:02:15.090Z

Link: CVE-2026-93171

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:12.830

Modified: 2026-09-17T17:18:12.830

Link: CVE-2026-93171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:30:16Z

Weaknesses