{"id":"CVE-2026-64429","summary":"gpio: eic-sprd: use raw_spinlock_t in the irq startup path","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: eic-sprd: use raw_spinlock_t in the irq startup path\n\nsprd_eic_irq_unmask() enables the GPIO IRQ and then updates controller\nstate through sprd_eic_update(), which takes sprd_eic-\u003elock with\nspin_lock_irqsave().  The callback can be reached from irq_startup()\nwhile setting up a requested IRQ.  That path is not sleepable, but on\nPREEMPT_RT a regular spinlock_t becomes a sleeping lock.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the request_threaded_irq() -\u003e __setup_irq() -\u003e\nirq_startup() -\u003e sprd_eic_irq_unmask() -\u003e sprd_eic_update() carrier and\nused the original spin_lock_irqsave(&sprd_eic-\u003elock) edge.  Lockdep\n\n  BUG: sleeping function called from invalid context\n  hardirqs last disabled at ... __setup_irq.constprop.0 ... [vuln_msv]\n  sprd_rt_spin_lock_irqsave+0x1c/0x30 [vuln_msv]\n  sprd_eic_update.constprop.0+0x48/0x90 [vuln_msv]\n  sprd_eic_irq_unmask.constprop.0+0x35/0x50 [vuln_msv]\n  __setup_irq.constprop.0+0xd/0x30 [vuln_msv]\n\nConvert the Spreadtrum EIC controller lock to raw_spinlock_t.  The\nlocked section only serializes MMIO register updates and does not contain\nsleepable operations, so keeping it non-sleeping is appropriate for the\nirqchip callbacks.","modified":"2026-07-27T04:03:19.957892031Z","published":"2026-07-25T08:51:06.016Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64429.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/19d63fd528719ce7d06d9aeb88d25b7d6478198a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4750909a40da9016185e0ac991510a278cecb1e7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/581ac2ad001ff1128931191f249a7f2074672b7a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6112fba4150039ccd90e29f2d1b788c73ad7b3dd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/90f0109019e6817eb40a486671b7722d1544ae29"},{"type":"WEB","url":"https://git.kernel.org/stable/c/96612bf2712cd961dbd9b52f3a9b4ab668f57628"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e244cd8b51001ba480f274c44dba9002813a4739"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64429.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64429"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"25518e024e3a6e5715d672f1daa91e1d100f7436"},{"fixed":"96612bf2712cd961dbd9b52f3a9b4ab668f57628"},{"fixed":"581ac2ad001ff1128931191f249a7f2074672b7a"},{"fixed":"e244cd8b51001ba480f274c44dba9002813a4739"},{"fixed":"19d63fd528719ce7d06d9aeb88d25b7d6478198a"},{"fixed":"6112fba4150039ccd90e29f2d1b788c73ad7b3dd"},{"fixed":"4750909a40da9016185e0ac991510a278cecb1e7"},{"fixed":"5c3c9ec1172a4c3384b8b800b3a8896cc2c1b20e"},{"fixed":"90f0109019e6817eb40a486671b7722d1544ae29"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64429.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.17.0"},{"fixed":"5.10.261"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.212"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.178"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.145"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.96"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.39"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64429.json"}}],"schema_version":"1.7.5"}