Junglewise Threat Intelligence

CVE-2026-23295: Linux Kernel amdxdna deadlock in suspend and resume

CVE-2026-23295 · Severity: medium · CVSS 5.5 · Published 2026-03-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw in the Linux kernel's AMD XDNA accelerator driver can cause the system to freeze or become unresponsive. This occurs when an application tries to communicate with the hardware at the same time the system is attempting to enter a low-power sleep mode. While this does not expose data, it can lead to a local denial-of-service where the affected hardware or the entire system stops responding.

Technical details

A deadlock exists in the accel/amdxdna driver due to improper locking (CWE-667) during suspend and resume operations. The vulnerability is triggered when a user-space application issues a query IOCTL while the kernel's auto-suspend mechanism is active. The query path acquires 'dev_lock' and then calls 'pm_runtime_resume_and_get()', which waits for the ongoing suspend to finish; however, the suspend callback is simultaneously blocked waiting for the same 'dev_lock'. This circular dependency results in a system hang. The fix involves releasing the lock before the runtime resume call and reacquiring it afterward.

Affected products

  • Linux Linux Kernel 6.19 to 6.19.7, 7.0-rc1

Timeline

  • 2026-03-25: advisory: CVE published by kernel.org
  • 2026-02-23: patched: Fix committed to mainline kernel

References