PT-2026-104862 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: au1000: move free irq out of the close-time spinlocked section
au1000 close() calls free irq() while aup->lock is still held with spin lock irqsave(). free irq() can sleep because it takes the IRQ descriptor request mutex, so it does not belong inside the close-time spinlocked section.
This was found by our static analysis tool and then confirmed by manual review of the in-tree au1000 close() .ndo stop path. The reviewed path keeps aup->lock held across the MAC reset, queue stop and free irq(dev->irq, dev).
A directed runtime validation kept that ndo stop carrier and the same free irq(dev->irq, dev) operation under the driver lock. Lockdep reported "BUG: sleeping function called from invalid context" and "Invalid wait context" while free irq() was taking desc->request mutex, with au1000 close() and free irq() on the stack.
Drop aup->lock before freeing the IRQ. The protected close-time work still stops the device and queue before IRQ teardown, but the sleepable IRQ core path now runs outside the spinlocked section.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103595

Affected Products

Kernel