Junglewise Threat Intelligence

CVE-2026-89589: Linux kernel acpi/apei/ghes spinlock deadlock in CXL CPER

CVE-2026-89589 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A deadlock condition exists in the Linux kernel's ACPI platform error interface when handling CXL (Compute Express Link) error notifications. If a CPU holding a spinlock is interrupted by a hardware error notification on the same CPU, the system can deadlock, potentially causing the kernel to hang and requiring a reboot. This affects Linux systems using CXL devices or capabilities.

Technical details

The vulnerability is a deadlock in acpi/apei/ghes caused by inconsistent lock acquisition modes on the cxl_cper_work_lock and cxl_cper_prot_err_work_lock. Registration functions acquire locks with spinlock_guard() (interrupts enabled), while post-event handlers acquire the same locks from hard IRQ context with irqsave guards. On a single CPU, if an IRQ arrives while the lock is held via spinlock_guard(), the IRQ handler spins waiting for the lock while the lock holder is preempted by the IRQ, causing deadlock. The fix converts both locks to raw_spinlock_t and consistently uses guard() at all call sites, ensuring safety in both normal and PREEMPT_RT kernel contexts. Additionally, the patch restructures unregister functions to clear global work pointers under lock before canceling work, preventing use-after-free scenarios.

Affected products

  • Linux Linux kernel various versions prior to the fix

Timeline

  • 2026-09-11: disclosed
  • 2026-09-11: patched

Related threats