Bug 2513328 (CVE-2026-68395) - CVE-2026-68395 kernel: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered
Summary: CVE-2026-68395 kernel: ata: sata_dwc_460ex: enable SATA interrupts only after...
Keywords:
Status: NEW
Alias: CVE-2026-68395
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-10 12:31 UTC by OSIDB Bzimport
Modified: 2026-08-12 22:07 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-10 12:31:15 UTC
In the Linux kernel, the following vulnerability has been resolved:

ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered

sata_dwc_enable_interrupts() is called before platform_get_irq() and
ata_host_activate(), leaving the SATA controller's interrupt mask
enabled without a registered handler.  If a later step fails (irq
request, phy init, etc.) or if the controller asserts an interrupt
during probe, the irq line may fire with no handler, causing a
spurious interrupt storm.

Move sata_dwc_enable_interrupts() after ata_host_activate() so that
interrupts are only unmasked once the handler is registered and the
core is fully initialized.


Note You need to log in before you can comment on or make changes to this bug.