Executive brief
The zynqmp_power driver in the Linux kernel manages power and system restart events on Xilinx platforms. A race condition exists where event handlers are registered before their associated work structures are allocated, allowing firmware to trigger callbacks that dereference NULL pointers if events fire between registration and initialization. This causes kernel crashes on affected systems.
Technical details
The vulnerability is a race condition (CWE-362) in the zynqmp_power driver's event initialization code. The driver registers event handlers via register_event() before allocating and initializing the work queue structures (zynqmp_pm_init_suspend_work and zynqmp_pm_init_restart_work) used by those handlers. If firmware triggers an event immediately after registration but before allocation completes, the suspend_event_callback or subsystem_restart_event_callback functions will call work_pending() on a NULL pointer, causing a kernel panic. No authentication or user interaction is required—only that the system firmware sends an event. The fix moves the devm_kzalloc() and INIT_WORK() calls to occur before the register_event() calls, closing the race window.
Affected products
- Linux Linux kernel multiple versions (race condition likely present from introduction of subsystem restart support until patched)
Timeline
- 2026-08-28: disclosed: CVE-2026-80655 published on NVD
- 2026-03-19: patched: Upstream fix committed by Prasanna Kumar T S M
- 2026-07-24: patched: Stable kernel backport merged by Greg Kroah-Hartman