PT-2026-93586 · Linux · Linux Kernel

CVE-2026-89945

·

Published

2026-09-16

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ASOC cs35l34 driver where the cs35l34 runtime suspend() function powers off the device and enables cache-only mode without first quiescing the threaded IRQ registered by devm request threaded irq(). This creates a race condition allowing cs35l34 irq thread() to execute after hardware access has been removed. During runtime power management, if the threaded handler runs while critical fault IRQs are unmasked, it may read volatile INT STATUS 1..4 registers, ignore read failures, and incorrectly execute the PROT RELEASE CTL release sequence or BST fault power-down writes.
Recommendations As a temporary mitigation, restrict the use of the cs35l34 codec driver during runtime power management transitions if possible. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-101454
CVE-2026-89945
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel