Junglewise Threat Intelligence

CVE-2026-72063: Linux kernel Tegra GPIO sleep-in-atomic context bug

CVE-2026-72063 · Severity: info · CVSS 0 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Tegra GPIO driver contains a bug where GPIO direction operations can inadvertently sleep while holding atomic locks, potentially causing kernel hangs or crashes on devices that use the Tegra GPIO controller. This affects system stability on Tegra-based embedded systems and mobile devices.

Technical details

The vulnerability is a sleep-in-atomic bug in the Tegra GPIO direction functions (tegra_gpio_direction_input/output). These functions call pinctrl_gpio_direction_input/output() unnecessarily; the Tegra pinmux ops provide GPIO request/free handling but no gpio_set_direction hook, making the pinctrl calls redundant. However, these redundant calls still acquire the pinctrl core mutex (pctldev->mutex), which can sleep. Shared GPIO users holding a per-line spinlock can trigger this code path, leading to a sleep-in-atomic violation. The fix removes the redundant pinctrl direction calls and relies only on the existing request/free path for pinctrl involvement, eliminating the mutex acquisition in the direction callback.

Affected products

  • Linux Linux kernel affected versions not specified

Timeline

  • 2026-08-15: disclosed

Related threats