CVE-2026-90193

Source
https://cve.org/CVERecord?id=CVE-2026-90193
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90193.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90193
Downstream
Published
2026-09-17T16:07:13Z
Modified
2026-09-18T03:48:36Z
Summary
mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler
Details

In the Linux kernel, the following vulnerability has been resolved:

mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding chan->lock. Under PREEMPT_RT, spin_lock_irqsave() is converted to an rt_spinlock (rtmutex-based), which tracks ownership and can sleep.

The callback chain triggered by mbox_chan_received_data() eventually reaches mailbox_clear_channel() -> mbox_send_message() -> add_to_rbuf(), which attempts to re-acquire the same chan->lock. Since rtmutex detects the re-entrant lock attempt by the same owner, the thread blocks waiting for a lock it already holds, causing a permanent deadlock.

This deadlock manifests as 'irq/N-apss_cpucp_mbox' stuck in D state with the following call trace: rt_spin_lock -> mbox_send_message -> mailbox_clear_channel -> scmi_rx_callback -> mbox_chan_received_data [<- held chan->lock here]

Fix by saving chan->cl locally and clearing the HW interrupt register inside the lock, then invoking mbox_chan_received_data() after releasing the lock. This preserves the mutual exclusion for chan->cl access while avoiding the lock re-entrancy that causes the PREEMPT_RT deadlock.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90193.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0e2a9a03106cd5fa0dbc9047675e7645c55e2669
Fixed
aa482273f32117c3adeba9b1cc945e0b5d33722d
Fixed
8b8de6400c86937ed57d680d06d716e167b381de
Fixed
e40b3edeaf25cd09e9c88edb1ef99373ca37593b
Fixed
3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90193.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.11.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90193.json"