CVE-2026-64587

Source
https://cve.org/CVERecord?id=CVE-2026-64587
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64587.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64587
Downstream
Published
2026-08-06T07:06:27.765Z
Modified
2026-08-08T03:48:19.083217889Z
Summary
net: ethernet: arc: emac: quiesce interrupts before requesting IRQ
Details

In the Linux kernel, the following vulnerability has been resolved:

net: ethernet: arc: emac: quiesce interrupts before requesting IRQ

Normal RX/TX interrupts are enabled later, in arcemacopen(), so probe should not see interrupt delivery in the usual case. However, hardware may still present stale or latched interrupt status left by firmware or the bootloader.

If probe later unwinds after devmrequestirq() has installed the handler, such a stale interrupt can still reach arcemacintr() during teardown and race with release of the associated net_device.

Avoid that window by putting the device into a known quiescent state before requesting the IRQ: disable all EMAC interrupt sources and clear any pending EMAC interrupt status bits. This keeps the change hardware-focused and minimal, while preventing spurious IRQ delivery from leftover state.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64587.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e4f2379db6c6823c5d4a4c2c912df00c65de51d7
Fixed
abd338da658d7faa8e26cfefc8f83f0066707564
Fixed
5f29dd540fe5ea3c826fc8ec759ba488b31f9707
Fixed
6fc7449773748c7b904235a09a67054d78ab1172
Fixed
81431da777924dddaefa5c9b0ca9da4a93f9df96
Fixed
d0f2386f529807826e7404d40a245ee428f89f62
Fixed
8efd5dcd31e22a9308b16b107a052fcd568c0a99
Fixed
8f9adb3605e36f75639de529bb3d66e94194a388
Fixed
2503d08f8a2de618e5c3a8183b250ff4a2e2d52c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64587.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.11.0
Fixed
5.10.253
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.203
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.167
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.130
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.78
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.19
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64587.json"