gpio: tegra: do not call pinctrl for GPIO direction
In the Linux kernel, the following vulnerability has been resolved: gpio: tegra: do not call pinctrl for GPIO direction tegra_gpio_direction_input() and tegra_gpio_direction_output() already program the GPIO controller direction registers directly. The additional pinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl operation, because the Tegra pinmux ops provide GPIO request/free handling but no gpio_set_direction hook. The extra call still enters the pinctrl core and takes pctldev->mutex. Shared GPIO users can call the direction path while holding their per-line spinlock, so this otherwise redundant pinctrl direction call can sleep in an atomic context. This was found by our static analysis tool and then confirmed by manual review of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the Tegra pinctrl ops. The reviewed path has a default non-sleeping struct gpio_chip while the direction callback still enters the pinctrl mutex path. A directed runtime validation kept the same non-sleeping chip registration and drove: gpio_shared_proxy_direction_output() gpiod_direction_output_raw_commit() tegra_gpio_direction_output() pinctrl_gpio_direction_output() Lockdep reported a sleep-in-atomic warning with the shared GPIO spinlock held and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output() on the stack. Do not mark the whole chip as can_sleep to paper over this: can_sleep describes whether get()/set() may sleep, and Tegra value access is MMIO. Remove the redundant pinctrl direction calls and keep pinctrl involvement in the existing request/free path.
- Published
- Aug 15, 2026
- Updated
- Aug 23, 2026
- EPSS
- 0.2% · 11th percentile
- CWE
- —
Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.
Report tools
Action score
0
Monitor
Low priority for now.
- CVSS
- 0 / 40 · —
- CISA KEV
- 0 / 30 · Not listed
- EPSS
- 0 / 30 · 0.2%
Noroxi analysis
No Noroxi analysis for this record yet
We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.
We use this product, ask for helpAffected systems
—
Versions reported by the vendor
Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.
Linux Linux
- 5.1affected
- 11da905412833d9b369a6a09a401f87149d674dc and later · before 89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49affected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before d3b92d16e1c4debec7526b6dbb2d98d0aeed796baffected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before 616188becd4a208afbae1653fc5241e1748bae80affected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before e57a4845b0da60a7b9f052160878097826320954affected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before cd17c5a1d9f186b57e9e2949be427803b7110a5caffected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before ac761e66708d51dac35c4c7f1891ea991dc788f0affected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before 628c63f96f4564fa145f602af2d41daf9532201faffected · git
- 11da905412833d9b369a6a09a401f87149d674dc and later · before d3e91a95b2b0fc6336dbf3ec90d831a1654d2720affected · git
- before 5.1not affected · semver
Package-level exposure
OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.
| Ecosystem | Package | Affected range | Fix |
|---|---|---|---|
| Debian:12 | linux | before 6.1.187-1 | 6.1.187-1 |
| Debian:13 | linux | before 6.12.100-1 | 6.12.100-1 |
| Debian:14 | linux | before 7.1.5-1 | 7.1.5-1 |
Same product
linux: all recordsOther highest-scoring records for the same primary product.
- CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation40Plan
- CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment40Plan
- CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()40Plan
- CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler40Plan
- CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index40Plan
- CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index40Plan
Remediation
Which version to upgrade to
Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.
| Product / package | Fixed version | Source |
|---|---|---|
| Linux Linux | 616188becd4a208afbae1653fc5241e1748bae80 | Vendor (CNA) |
| Linux Linux | 628c63f96f4564fa145f602af2d41daf9532201f | Vendor (CNA) |
| Linux Linux | 89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49 | Vendor (CNA) |
| Linux Linux | ac761e66708d51dac35c4c7f1891ea991dc788f0 | Vendor (CNA) |
| Linux Linux | cd17c5a1d9f186b57e9e2949be427803b7110a5c | Vendor (CNA) |
| Linux Linux | d3b92d16e1c4debec7526b6dbb2d98d0aeed796b | Vendor (CNA) |
| Linux Linux | d3e91a95b2b0fc6336dbf3ec90d831a1654d2720 | Vendor (CNA) |
| Linux Linux | e57a4845b0da60a7b9f052160878097826320954 | Vendor (CNA) |
| debian:linux | 6.1.187-1 · Debian:12 | Package registry (OSV) |
Exploit status
No known public exploit
No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.
Research context
For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.
Timeline
From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.
No dated events beyond publication.
FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).
Patch and commit links
Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.
No commit or PR link among the references.
Credits
All researchersFinders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.
No credits in the CNA record.
Variant candidates
Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.
No nightly-computed relations.
Chain candidates
An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.
—
Bug bounty scope
No known public program.
Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).
Technical details
No CVSS vector for this record, so attack conditions can't be derived.
Weakness class (CWE)
—
Attack context
MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.
MITRE has no CAPEC/ATT&CK mapping for this CWE.
Change log
- Fix✗ → ✓
For records you follow, these changes also arrive as notifications. →
References
- git.kernel.org/stable/c/616188becd4a208afbae1653fc5241e1748bae80
- git.kernel.org/stable/c/628c63f96f4564fa145f602af2d41daf9532201f
- git.kernel.org/stable/c/89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49
- git.kernel.org/stable/c/ac761e66708d51dac35c4c7f1891ea991dc788f0
- git.kernel.org/stable/c/cd17c5a1d9f186b57e9e2949be427803b7110a5c
- git.kernel.org/stable/c/d3b92d16e1c4debec7526b6dbb2d98d0aeed796b
- git.kernel.org/stable/c/d3e91a95b2b0fc6336dbf3ec90d831a1654d2720
- git.kernel.org/stable/c/e57a4845b0da60a7b9f052160878097826320954
Vendor advisories and official records. Exploit/PoC links are deliberately left out.