PT-2026-94541 · Linux · Linux Kernel

CVE-2026-90193

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A self-deadlock occurs in the IRQ handler of the qcom-cpucp mailbox. The function qcom cpucp mbox irq fn() calls mbox chan received data() while holding chan->lock. In PREEMPT RT configurations, spin lock irqsave() is converted to an rt spinlock (a mutex-based lock that tracks ownership and can sleep). The subsequent callback chain leads to mailbox clear channel(), mbox send message(), and finally add to rbuf(), which attempts to re-acquire chan->lock. Because the rtmutex detects a re-entrant lock attempt by the same owner, the thread blocks indefinitely, resulting in a permanent deadlock where the process remains stuck in D state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90193
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel