CVE-2026-68395

Unknown

Last modified

CVE-2026-68395 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler. If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm. Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized..

Description

In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler. If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm. Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 62936009f35a6659cc3ebe0d90c754182d60da73, < fbe7df5d3a3aed2456667a4825e4ff98d6df6ca4; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 23d4c50fdc0dfe3ad4f9647a3b7d486de807dcda; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < daa80b422ed920a3c0c45153020b0ad7af7fb5a5; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 5d0797d6940b8dc894f950c52f7af0b42cb55ed0; >= 62936009f35a6659cc3ebe0d90c754182d60da73, < 4bbc16a353a98023e5ddfca7c1fc0e49971cf4d0
LinuxLinux2.6.36

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-68395?
In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered sata_dwc_enable_interrupts() is called before platform_get_irq() and ata_host_activate(), leaving the SATA controller's interrupt mask enabled without a registered handler. If a later step fails (irq request, phy init, etc.) or if the controller asserts an interrupt during probe, the irq line may fire with no handler, causing a spurious interrupt storm. Move sata_dwc_enable_interrupts() after ata_host_activate() so that interrupts are only unmasked once the handler is registered and the core is fully initialized.
How severe is CVE-2026-68395?
Severity scoring for CVE-2026-68395 is pending analysis.
How do I fix CVE-2026-68395?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-68395?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST