Executive brief
A timeout issue in the Linux kernel's virtio RTC (real-time clock) driver can cause device removal to hang when an alarm request is pending and the virtual device becomes unresponsive. This affects systems using virtio-based RTC devices, potentially delaying or blocking device hotplug and system shutdown operations.
Technical details
The vulnerability is a missing timeout in the virtio RTC driver's alarm request handling. RTC class operations execute while holding rtc_device.ops_lock. Alarm requests (read, set, and interrupt enable) previously waited indefinitely for device responses without a timeout, unlike clock read requests which used a 60-second timeout. On device surprise removal, virtio-pci marks virtqueues as broken before unregistering the device. If an alarm request is pending when this occurs, viortc_remove() blocks indefinitely while trying to acquire ops_lock, preventing the request from completing and causing device removal to hang. The fix applies a consistent 60-second timeout to all alarm request types, allowing them to fail gracefully if the device becomes unresponsive.
Affected products
- Linux Linux kernel prior to fix commit 68e00d9212929805b40dcb9166755610f4f4acee
Timeline
- 2026-09-17: disclosed
- 2026-08-19: patched