Executive brief
A deadlock condition exists in the Linux kernel's ACPI platform error interface when handling CXL (Compute Express Link) error notifications. If a CPU holding a spinlock is interrupted by a hardware error notification on the same CPU, the system can deadlock, potentially causing the kernel to hang and requiring a reboot. This affects Linux systems using CXL devices or capabilities.
Technical details
The vulnerability is a deadlock in acpi/apei/ghes caused by inconsistent lock acquisition modes on the cxl_cper_work_lock and cxl_cper_prot_err_work_lock. Registration functions acquire locks with spinlock_guard() (interrupts enabled), while post-event handlers acquire the same locks from hard IRQ context with irqsave guards. On a single CPU, if an IRQ arrives while the lock is held via spinlock_guard(), the IRQ handler spins waiting for the lock while the lock holder is preempted by the IRQ, causing deadlock. The fix converts both locks to raw_spinlock_t and consistently uses guard() at all call sites, ensuring safety in both normal and PREEMPT_RT kernel contexts. Additionally, the patch restructures unregister functions to clear global work pointers under lock before canceling work, preventing use-after-free scenarios.
Affected products
- Linux Linux kernel various versions prior to the fix
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched