Executive brief
A vulnerability in the Linux kernel's IP Accelerator (IPA) driver can cause systems to hang indefinitely during power management operations or network data transfers. The IPA component is responsible for accelerating network data processing; when it fails, the entire data path becomes non-functional. This can lead to a complete loss of network connectivity and system responsiveness, impacting business operations and service availability.
Technical details
A logic error in the Linux kernel's IPA driver (specifically for IPA v5.0+) results in the event ring index not being correctly programmed. The field moved from the CH_C_CNTXT_0 register to CH_C_CNTXT_1 in version 5.0, but the driver continued to use an outdated identifier (ERINDEX instead of CH_ERINDEX) in the register definition. This prevents GSI channels from signaling transfer completions, causing the 'gsi_channel_trans_quiesce()' function to block indefinitely. The impact includes a non-functional IPA data path and permanent hangs during runtime suspend, system suspend, or remoteproc stop operations. Patches have been merged into multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel IPA v5.0+
Timeline
- 2026-04-03: other: Patch authored
- 2026-05-08: advisory: CVE published
References
- https://git.kernel.org/stable/c/2bf18b643c4656413f7cfd5615af60a6b4e261da
- https://git.kernel.org/stable/c/2d2dc166d55148cfcf8ae67b415f8d6d110e6fca
- https://git.kernel.org/stable/c/34c988bb04cbdf093d2134e179433da49ffcd044
- https://git.kernel.org/stable/c/56007972c0b1e783ca714d6f1f4d6e66e531d21f
- https://git.kernel.org/stable/c/ae8343a19ccb051d519dbb3a9082ddea9f0551d3