CVE-2026-80655

Source
https://cve.org/CVERecord?id=CVE-2026-80655
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80655.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80655
Downstream
Published
2026-08-28T06:49:01.988Z
Modified
2026-08-30T03:47:21.722056822Z
Summary
soc: xilinx: Fix race condition in event registration
Details

In the Linux kernel, the following vulnerability has been resolved:

soc: xilinx: Fix race condition in event registration

The zynqmppower driver registers handlers for suspend and subsystem restart events using registerevent(). However, the work structures (zynqmppminitsuspendwork and zynqmppminitrestartwork) used by these handlers were allocated and initialized after the registration call.

This created a race window where, if the firmware triggered an event immediately after registration but before allocation, the callback (suspendeventcallback or subsystemrestarteventcallback) would dereference a NULL pointer in workpending(), leading to a crash.

Fix this by allocating and initializing the work structures before registering the events.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80655.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
fcf544ac64397776a18246eba5a8ca72a47c4405
Fixed
d349aa118ff5e4cab88424ce1b16e08edd70f8bb
Fixed
fb445935338405110baca8f541a2df3b4cb8d712

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80655.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80655.json"