{"id":"CVE-2026-64587","summary":"net: ethernet: arc: emac: quiesce interrupts before requesting IRQ","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: arc: emac: quiesce interrupts before requesting IRQ\n\nNormal RX/TX interrupts are enabled later, in arc_emac_open(), so probe\nshould not see interrupt delivery in the usual case. However, hardware may\nstill present stale or latched interrupt status left by firmware or the\nbootloader.\n\nIf probe later unwinds after devm_request_irq() has installed the handler,\nsuch a stale interrupt can still reach arc_emac_intr() during teardown and\nrace with release of the associated net_device.\n\nAvoid that window by putting the device into a known quiescent state before\nrequesting the IRQ: disable all EMAC interrupt sources and clear any\npending EMAC interrupt status bits. This keeps the change hardware-focused\nand minimal, while preventing spurious IRQ delivery from leftover state.","modified":"2026-08-09T03:47:26.462616333Z","published":"2026-08-06T07:06:27.765Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64587.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/2503d08f8a2de618e5c3a8183b250ff4a2e2d52c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5f29dd540fe5ea3c826fc8ec759ba488b31f9707"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6fc7449773748c7b904235a09a67054d78ab1172"},{"type":"WEB","url":"https://git.kernel.org/stable/c/81431da777924dddaefa5c9b0ca9da4a93f9df96"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8efd5dcd31e22a9308b16b107a052fcd568c0a99"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8f9adb3605e36f75639de529bb3d66e94194a388"},{"type":"WEB","url":"https://git.kernel.org/stable/c/abd338da658d7faa8e26cfefc8f83f0066707564"},{"type":"WEB","url":"https://git.kernel.org/stable/c/d0f2386f529807826e7404d40a245ee428f89f62"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64587.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64587"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"e4f2379db6c6823c5d4a4c2c912df00c65de51d7"},{"fixed":"abd338da658d7faa8e26cfefc8f83f0066707564"},{"fixed":"5f29dd540fe5ea3c826fc8ec759ba488b31f9707"},{"fixed":"6fc7449773748c7b904235a09a67054d78ab1172"},{"fixed":"81431da777924dddaefa5c9b0ca9da4a93f9df96"},{"fixed":"d0f2386f529807826e7404d40a245ee428f89f62"},{"fixed":"8efd5dcd31e22a9308b16b107a052fcd568c0a99"},{"fixed":"8f9adb3605e36f75639de529bb3d66e94194a388"},{"fixed":"2503d08f8a2de618e5c3a8183b250ff4a2e2d52c"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64587.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.11.0"},{"fixed":"5.10.253"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.203"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.167"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.78"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.19"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.9"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64587.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}