CVE-2026-90124

Source
https://cve.org/CVERecord?id=CVE-2026-90124
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90124.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90124
Downstream
Published
2026-09-17T16:06:27Z
Modified
2026-09-19T03:47:28Z
Summary
irqchip/renesas-rzg2l: Fix loss of interrupt
Details

In the Linux kernel, the following vulnerability has been resolved:

irqchip/renesas-rzg2l: Fix loss of interrupt

rzg2l_clear_irq_int() and rzg2l_clear_tint_int() perform a read-modify-write on the ISCR/TSCR status registers to clear the bit for the interrupt just handled. Since these registers are write-0-to-clear per bit, this is racy:

If another interrupt's status bit gets set between the read and the write, that bit is written back as 0 by the software-constructed value, clearing an interrupt that hasn't been serviced yet and losing it.

This can be reproduced by triggering multiple interrupts at once, e.g.:

gpioset -c gpiochip0 355=0 353=0 328=0 352=0

Fix this by writing back only the bit being cleared, with all other bits set to 1, instead of read-modify-writing the whole register. Since 1-bits are left unchanged by hardware, concurrently-set status bits for other interrupts are preserved.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90124.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3fed09559cd8be79568d368ce02bf7f2d56259b6
Fixed
c043591f03a8111f7d306b8122c444a949486269
Fixed
b5ba8b861b5d833394bd23df3f4b59883ef18c88
Fixed
3791e242ec2e5a5cd9e010a75ed1125d0e84d394
Fixed
38c6831fefde0ff89f8d2dcb924f957a89dec414
Fixed
dbecbe23dc606c4af68b4591a41124186f5c1802
Fixed
50b10bd0c2d721ad38abd1abe3acdefb6caa0944

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90124.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90124.json"