CVE-2026-98094

Source
https://cve.org/CVERecord?id=CVE-2026-98094
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98094.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98094
Downstream
Published
2026-09-25T10:24:25Z
Modified
2026-09-26T03:48:32Z
Summary
staging: fbtft: make dirty_lock IRQ-safe
Details

In the Linux kernel, the following vulnerability has been resolved:

staging: fbtft: make dirty_lock IRQ-safe

fbtft_mkdirty() can be reached from the fbcon rendering path while processing printk() in hardirq context. Meanwhile, dirty_lock is also taken by fbtft_deferred_io() in workqueue context with local interrupts enabled.

Lockdep reports a possible IRQ lock inversion involving dirty_lock and console_owner. A hardirq can interrupt a CPU holding dirty_lock and enter the console rendering path, which can attempt to acquire dirty_lock again.

The following lockdep report was observed on an RK3566 system with CONFIG_PROVE_LOCKING enabled:

WARNING: possible irq lock inversion dependency detected swapper/2/0 just changed the state of lock: (console_owner){-...}-{0:0} but this lock took another, HARDIRQ-unsafe lock in the past: (&par->dirty_lock){+.+.}-{2:2}

CPU0 CPU1


lock(&par->dirty_lock); local_irq_disable(); lock(console_owner); lock(&par->dirty_lock); lock(console_owner);

*** DEADLOCK ***

Use spin_lock_irqsave() for fbtft_mkdirty() and spin_lock_irq() for fbtft_deferred_io(). They only access the dirty line range, so the IRQ-off regions remain short.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98094.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c296d5f9957c03994a699d6739c27d4581a9f6c7
Fixed
2a609e29efbba79f9abd68c4ec8a2bd7ecf291e7
Fixed
f0c869df2c33793c8828acaab3e4a5e0176f9f00
Fixed
dcb48fde8003492256dee45815144aa5ed26ce7c
Fixed
f576944a59f31bcffff121117ebf452c5dd162b7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98094.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
6.12.111
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.53
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98094.json"