CVE-2026-74331
CVE CVE-2026-74331EUVD EUVD-2026-59478Veröffentlicht 2026-08-15T05:58:24.000ZZuletzt geändert 2026-08-17T05:17:22.000Z
Was das Advisory beschreibt
In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Fix recursive lock in device_cache_fw_images() A recursive locking deadlock can occur in the firmware loader's power management notification handler. During system suspend or hibernation preparation, fw_pm_notify() calls device_cache_fw_images(). This function acquires fw_lock to set the firmware cache state to FW_LOADER_START_CACHE and then iterates over all devices using dpm_for_each_dev() while still holding the lock. For each device, dev_cache_fw_image() schedules asynchronous work to cache the firmware. If memory allocation for the async work entry fails (e.g., in out-of-memory conditions), async_schedule_node_domain() falls back to executing the work function synchronously in the current thread. The synchronous execution path (__async_dev_cache_fw_image() -> cache_firmware() -> request_firmware() -> assign_fw()) attempts to acquire fw_lock again. Since the current thread already holds fw_lock, this results in a recursive locking deadlock. Fix this by releasing fw_lock immediately after updating the cache state and before calling dpm_for_each_dev(). The lock is only needed to protect the state update. Concurrent firmware requests will correctly see the FW_LOADER_START_CACHE state and use the piggyback mechanism, which is independently protected by its own fwc->name_lock.
Quelle: EUVD (ENISA), im Wortlaut der Meldung.
Produkte, die das Advisory nennt
Diese Angaben stammen aus der Meldung selbst, nicht aus einer Prüfung durch uns.
- Linux — Linux patch: 6.1.178; 3.7; patch: 7.2; patch: 7.1.5; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <d3ec78f8f8d48a04a9fac38d47275c34645e5103; patch: 5.10.261; patch: 5.15.212; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <806cb8fabfde7f830da5ae87777d52fdf50c4774; patch: 6.18.40; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <7865a1bfd20d10c03b083a5fc392d907ca5099b3; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <f25d6e4ec4c257030592bd671f113cf9584c52f0; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <c0f2dedd41fe14dbe076c1672214802fb42cd8c8; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <38149b57427c736c08d9aa4c7b87deacd53e9e63; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <490b0385e4cfac691f7b18dde821c13e77b4770b; patch: 6.6.145; patch: 0; patch: 6.12.97; ac39b3ea73aacde876d1d5ee1ca3e2719f771482 <a5b2a68a391b05d54552f13548a72a46c65006f7
Die genannten Versionen sind die Angabe der Meldung. Patchlage vergleicht keine Versionsnummern und leitet aus ihnen keine Aussage ab — welche Version installiert ist, muss ein Mensch nachsehen.
Im Produktkatalog geführt
Für diese Produkte kann ein Bestand in Patchlage erfasst werden. Ein Advisory dazu erscheint am Morgen danach im Lagebericht.
- Linux — Linux
Betrifft das einen Ihrer Kundenbestände?
Diese Seite kann die Frage nicht beantworten — sie kennt Ihren Bestand nicht. Wer seine Umgebungen erfasst hat, bekommt die Antwort am Morgen nach der Veröffentlichung, zusammen mit einem Absatz, den er unverändert an den Kunden weitergeben kann.
28 Tage testenPatchlage meldet Treffer und Verdachtsfälle. Zu allem anderen sagt dieses System nichts — weder diese Seite noch der Lagebericht behauptet je, dass ein Bestand sicher ist.