Junglewise Threat Intelligence

CVE-2026-23470: Linux Kernel deadlock in drm/imagination soft reset sequence

CVE-2026-23470 · Severity: medium · CVSS 5.5 · Published 2026-04-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Imagination Technologies graphics driver could allow a local user to cause a system deadlock. This occurs during a specific hardware reset process, potentially leading to a complete system hang or denial of service. This impact primarily affects system availability and operational stability.

Technical details

A deadlock exists in the 'drm/imagination' driver within the 'pvr_power_reset' function in 'drivers/gpu/drm/imagination/pvr_power.c'. The vulnerability is caused by calling 'disable_irq()' from within a threaded interrupt (IRQ) handler during a soft reset. Because 'disable_irq()' waits for the IRQ handler to complete, and it is being called by the handler itself, a circular dependency (deadlock) occurs. The fix replaces 'disable_irq()' with 'disable_irq_nosync()' for soft resets, which does not wait for the current handler to finish. This issue is reachable by local users and results in a denial of service (system hang).

Affected products

  • Linux Linux Kernel 6.8 to 6.12.78, 6.13 to 6.18.20, 6.19 to 6.19.10, 7.0-rc1 to 7.0-rc4

Timeline

  • 2026-03-09: other: Patch authored
  • 2026-04-03: disclosed: CVE published
  • 2026-05-26: advisory: NVD enrichment and analysis completed

References