VYPR
Medium severity5.5NVD Advisory· Published Jul 24, 2026· Updated Aug 13, 2026

CVE-2026-64238

CVE-2026-64238

Description

In the Linux kernel, the following vulnerability has been resolved:

gpio: shared: fix deadlock on shared proxy's parent removal

Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set") used the mutex embedded in struct gpio_shared_entry to protect the offset field which now can be modified after assignment. The critical section however is too wide and introduced a potential deadlock on the removal of the shared GPIO proxy's parent.

Make the critical section shorter - only protect the offset when it's being read.

While at it: mention the fact that the entry lock is now also used to protect against concurrent access to the offset field in the structure's documentation.

Affected products

10
  • Linux/Kernel9 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.19.12,<7.0
    • cpe:2.3:o:linux:linux_kernel:7.0:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.1:rc5:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 7.0.0, < 7.0.12

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.