PT-2026-104862 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: au1000: move free irq out of the close-time spinlocked section
au1000 close() calls free irq() while aup->lock is still held with
spin lock irqsave(). free irq() can sleep because it takes the IRQ
descriptor request mutex, so it does not belong inside the close-time
spinlocked section.
This was found by our static analysis tool and then confirmed by manual
review of the in-tree au1000 close() .ndo stop path. The reviewed path
keeps aup->lock held across the MAC reset, queue stop and
free irq(dev->irq, dev).
A directed runtime validation kept that ndo stop carrier and the same
free irq(dev->irq, dev) operation under the driver lock. Lockdep reported
"BUG: sleeping function called from invalid context" and "Invalid wait
context" while free irq() was taking desc->request mutex, with
au1000 close() and free irq() on the stack.
Drop aup->lock before freeing the IRQ. The protected close-time work still
stops the device and queue before IRQ teardown, but the sleepable IRQ core
path now runs outside the spinlocked section.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel