CVE-2026-23071
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave routine Previously, the address of the shared member '&map->spinlock_flags' was passed directly to 'hwspin_lock_timeout_irqsave'.
Does this matter?
Lower severity and a low EPSS score (0.10%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave routine Previously, the address of the shared member '&map->spinlock_flags' was passed directly to 'hwspin_lock_timeout_irqsave'. This creates a race condition where multiple contexts contending for the lock could overwrite the shared flags variable, potentially corrupting the state for the current lock owner. Fix this by using a local stack variable 'flags' to store the IRQ state temporarily.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.10% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/24f31be6ad70537fd7706269d99c92cade465a09Patch
- https://git.kernel.org/stable/c/4aab0ca0a0f7760e33edcb4e47576064d05128f5Patch
- https://git.kernel.org/stable/c/4b58aac989c1e3fafb1c68a733811859df388250Patch
- https://git.kernel.org/stable/c/766e243ae8c8b27087a4cc605752c0d5ee2daeabPatch
- https://git.kernel.org/stable/c/c2d2cf710dc3ee1a69e00b4ed8de607a92a07889Patch
- https://git.kernel.org/stable/c/e1a7072bc4f958c9e852dc7e57e39f12b0bb44b5Patch
- https://git.kernel.org/stable/c/f1e2fe26a51eca95b41420af76d22c2e613efd5ePatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.