CVE-2026-97948
CVE CVE-2026-97948EUVD EUVD-2026-86802Published 2026-09-25T10:22:57.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: powerpc/eeh: Fix recursive locking on devices without EEH sensitive driver The commit 1010b4c012b0 ("powerpc/eeh: Make EEH driver device hotplug safe") refactored the EEH code such that the pci_rescan_remove_lock is held at the beginning of eeh_handle_normal_event() and the eeh_reset_device() is called with that lock being held. Looks like the commit missed to remove the existing lock/unlock inside eeh_rmv_device() which is no longer necessary. This is causing the eehd to hang on the lock which it actually holds when that code path is taken. [<0>] 0xc00000011c78f870 [<0>] __switch_to+0xfc/0x1a0 [<0>] pci_lock_rescan_remove+0x30/0x44 [<0>] eeh_rmv_device+0x290/0x2e0 [<0>] eeh_pe_dev_traverse+0x80/0x130 [<0>] eeh_reset_device+0xcc/0x23c [<0>] eeh_handle_normal_event+0x830/0xa80 [<0>] eeh_event_handler+0xf8/0x190 [<0>] kthread+0x194/0x1b0 [<0>] start_kernel_thread+0x14/0x18 The issue is seen for cases where the errors are detected on the PHB directly AND|OR for devices where the driver error_detected() returns PCI_ERS_RESULT_NEED_RESET, and driver being not EEH sensitive(i.e no error handlers like slot_reset(), resume() etc defined).
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 1010b4c012b0d78dfb9d3132b49aa2ef024a07a7 <c5e68706527968282e49de205cc2b935823cb88a; 59c6d3d81d42bf543c90597b4f38c53d6874c5a1; 6.12.42 <6.12.111; 19d5036e7ad766cf212aebec23b9f1d7924a62bc; 1010b4c012b0d78dfb9d3132b49aa2ef024a07a7 <85d8eaefc052cf3e5ae2c7bafeda2db68b8898b4; patch: 7.3-rc3; 5.10.241 <5.11; patch: 0; 1010b4c012b0d78dfb9d3132b49aa2ef024a07a7 <2920af33d097ca335e492b346af70b72986ad6dc; 5.15.190 <5.16; 502f08831a9afb72dc98a56ae6504da43e93b250; 6.15.10 <6.16; f56e004b781719d8fdf6c9619b15caf2579bc1f2; d2c60a8a387e9fcc28447ef36c03f8e49fd052a6 <102e3dc5ab5ba052e294819e83384166b242c1ec; 6.16.1 <6.17; patch: 6.12.111; 6.6.102 <6.7; patch: 7.2.7; d42bbd8f30ac38b1ce54715bf08ec3dac18d6b25; 6.17; patch: 6.18.53; a426e8a6ae161f51888585b065db0f8f93ab2e16; 6.1.148 <6.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.