CVE-2026-89945
Last modified
CVE-2026-89945 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ASoC: cs35l34: drain threaded IRQ before runtime suspend cs35l34_runtime_suspend() currently switches the codec into regcache_cache_only(true), asserts reset low, and powers the device off without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l34_irq_thread() can still run after suspend has removed live hardware access. A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: cs35l34: drain threaded IRQ before runtime suspend cs35l34_runtime_suspend() currently switches the codec into regcache_cache_only(true), asserts reset low, and powers the device off without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l34_irq_thread() can still run after suspend has removed live hardware access. A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked. If the threaded handler runs in that window, it reads volatile INT_STATUS_1..4 after cache_only has been enabled, ignores the regmap_read() failures, and can still execute the PROT_RELEASE_CTL release sequence or the BST fault power-down writes. Use disable_irq() before entering cache_only/reset-low/power-off so any in-flight threaded handler is drained and no new IRQ thread can run while the device is suspended. Re-enable the IRQ only after runtime_resume() has restored live register access with regcache_sync(). Since probe only logs request_threaded_irq() failures and keeps going, track whether the IRQ was actually installed before disabling or re-enabling it.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 3be8380fb14d602cd833e5852e6d83c1e7eb1ceb; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 96982734e765c13c3db02067e1d5784682085f5c; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 5b063739619990d5de0c94c85d6e5be14e7cbdfe; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < f4bfd755c52dfa7584e6c9374206b71b8895c997; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 4fe8a91a9266f1321c2d31ce67940a4e8b93559e; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 5a4fe7a87841af23ba80bae31b80355b16926cf4; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 07a86575edc308e66b6c8873ed4a93ef3a063e55; >= c1124c09e1035cabdbc17d4538ae6f922086fec9, < 4105a4c0678b2808fc8046b60321b4f1cc7dae75 |
| Linux | Linux | 4.10 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89945?
How severe is CVE-2026-89945?
How do I fix CVE-2026-89945?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8994The Login with NEAR plugin for WordPress is vulnerable to Au…8.1
- CVE-2026-89940In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89941In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89942In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89943In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-89944In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89946In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89947In the Linux kernel, the following vulnerability has been re…8
- CVE-2026-89948In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89949In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8995The Poll Maker – Versus Polls, Anonymous Polls, Image Polls …4.3
- CVE-2026-89950In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-89945?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
