Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: fsl_audmix: rework runtime PM handling in probe

After pm_runtime_enable() the AUDMIX block is powered off and stays
suspended until the first runtime resume. Register writes issued between
probe() and the first resume (e.g. from DAPM or ALSA control paths)
target unpowered hardware and cause a system hang.

Fix this by calling pm_runtime_resume_and_get() immediately after
pm_runtime_enable() to power the hardware up and enable its clocks.
Release the reference afterwards with pm_runtime_put() to allow the
runtime PM framework to suspend the device and switch the regmap to
cache-only mode when idle.

When CONFIG_PM is disabled or runtime PM is not enabled, pm_runtime_*
calls are stubs that do not power up the hardware. Handle this case
explicitly by calling fsl_audmix_runtime_resume() directly so the
hardware is always initialised and its clocks are enabled, ensuring
register accesses succeed regardless of PM configuration.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Register writes performed by the fsl_audmix driver while the device is still powered off cause the hardware to hang. This occurs between probe and the first runtime resume, when the PM framework has not yet enabled the clocks. The flaw is an initialization error that allows kernel code to write to a device that is not yet ready, resulting in a system halt. It aligns with the weakness of calling functions before a component’s state is valid, a common form of improper initialization.

Affected Systems

All Linux kernel builds that include the fsl_audmix component, regardless of vendor, are potentially affected when runtime PM is enabled. The issue is present in kernel versions that have not incorporated the commit series that restores correct PM handling, specifically those compiled with CONFIG_PM and without explicit hardware initialization during probe. The exact version range is not provided, so any kernel before the fix should be considered vulnerable, especially on hardware platforms that use the ALSA/fsl_audmix driver.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low exploitation probability. However, the vulnerability requires privileged kernel execution and access to the affected audio hardware, therefore it is a local denial‑of‑service risk. Exploitation would be straightforward once the driver loads; an attacker could trigger the hang by invoking any ALSA control that writes to the device after driver initialization. The severity of the impact is high for systems that rely on continuous audio processing, but the likelihood of targeted attacks remains low.

Generated by OpenCVE AI on September 19, 2026 at 08:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the commit which calls pm_runtime_resume_and_get() immediately after pm_runtime_enable() in the fsl_audmix probe.
  • If an upgrade is not possible, patch the driver source to insert pm_runtime_resume_and_get() after pm_runtime_enable() and subsequently call pm_runtime_put() to allow normal suspension logic.
  • Ensure that if CONFIG_PM is disabled, the driver explicitly invokes fsl_audmix_runtime_resume() during initialization so that the hardware is always powered and clocks enabled.
  • Verify that the build configuration sets CONFIG_PM=y and that run‑time PM is correctly enabled for the audio subsystem.
  • Recompile the kernel and reload the driver so the changes take effect.

Generated by OpenCVE AI on September 19, 2026 at 08:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-673

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl_audmix: rework runtime PM handling in probe After pm_runtime_enable() the AUDMIX block is powered off and stays suspended until the first runtime resume. Register writes issued between probe() and the first resume (e.g. from DAPM or ALSA control paths) target unpowered hardware and cause a system hang. Fix this by calling pm_runtime_resume_and_get() immediately after pm_runtime_enable() to power the hardware up and enable its clocks. Release the reference afterwards with pm_runtime_put() to allow the runtime PM framework to suspend the device and switch the regmap to cache-only mode when idle. When CONFIG_PM is disabled or runtime PM is not enabled, pm_runtime_* calls are stubs that do not power up the hardware. Handle this case explicitly by calling fsl_audmix_runtime_resume() directly so the hardware is always initialised and its clocks are enabled, ensuring register accesses succeed regardless of PM configuration.
Title ASoC: fsl_audmix: rework runtime PM handling in probe
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:10.782Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.430

Modified: 2026-09-17T17:18:14.430

Link: CVE-2026-93184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:11Z

Weaknesses
  • CWE-673

    External Influence of Sphere Definition