Executive brief
The Linux kernel's pca953x GPIO driver contains a race condition in interrupt handling that could allow multiple threads to read or write incorrect GPIO register values. This affects systems using PCA953X-series GPIO expander chips, which are commonly used in network appliances and embedded devices to extend GPIO capabilities. An attacker with local access could potentially cause unpredictable behavior in GPIO-controlled hardware, leading to service disruption or unauthorized state changes.
Technical details
The vulnerability is a missing synchronization in the pca953x_irq_bus_sync_unlock() function within drivers/gpio/gpio-pca953x.c. The driver disables locking at the regmap level and relies on an i2c_lock for all register access. The pca953x_irq_bus_sync_unlock() function performs both reads (from the direction register) and writes (to the interrupt mask register) without holding the required i2c_lock, creating a race condition where concurrent threads can interleave these operations and access incorrect registers. The fix adds explicit lock acquisition at the beginning of pca953x_irq_bus_sync_unlock() and refactors pca953x_gpio_direction_input() into locked and unlocked variants to avoid deadlock. The vulnerability requires local kernel execution context but no special privileges.
Affected products
- Linux Linux kernel Multiple versions (all supporting pca953x GPIO driver)
Timeline
- 2026-08-22: disclosed