Skip to content
Noroxi
CVE-2026-72063· NVD / CVE Program· CNA Linux

gpio: tegra: do not call pinctrl for GPIO direction

In the Linux kernel, the following vulnerability has been resolved: gpio: tegra: do not call pinctrl for GPIO direction tegra_gpio_direction_input() and tegra_gpio_direction_output() already program the GPIO controller direction registers directly. The additional pinctrl_gpio_direction_input/output() calls do not add a Tegra pinctrl operation, because the Tegra pinmux ops provide GPIO request/free handling but no gpio_set_direction hook. The extra call still enters the pinctrl core and takes pctldev->mutex. Shared GPIO users can call the direction path while holding their per-line spinlock, so this otherwise redundant pinctrl direction call can sleep in an atomic context. This was found by our static analysis tool and then confirmed by manual review of tegra_gpio_probe(), the Tegra GPIO direction callbacks and the Tegra pinctrl ops. The reviewed path has a default non-sleeping struct gpio_chip while the direction callback still enters the pinctrl mutex path. A directed runtime validation kept the same non-sleeping chip registration and drove: gpio_shared_proxy_direction_output() gpiod_direction_output_raw_commit() tegra_gpio_direction_output() pinctrl_gpio_direction_output() Lockdep reported a sleep-in-atomic warning with the shared GPIO spinlock held and pinctrl_get_device_gpio_range() plus tegra_gpio_direction_output() on the stack. Do not mark the whole chip as can_sleep to paper over this: can_sleep describes whether get()/set() may sleep, and Tegra value access is MMIO. Remove the redundant pinctrl direction calls and keep pinctrl involvement in the existing request/free path.

—No exploit Fix available
Published
Aug 15, 2026
Updated
Aug 23, 2026
EPSS
0.2% · 11th percentile
CWE
—
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

0

Monitor

Low priority for now.

CVSS
0 / 40 · —
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.2%

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for the hundreds of thousands of vulnerabilities in the database; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Affected systems

—

Versions reported by the vendor

Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.

  • Linux Linux

    • 5.1affected
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before 89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49affected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before d3b92d16e1c4debec7526b6dbb2d98d0aeed796baffected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before 616188becd4a208afbae1653fc5241e1748bae80affected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before e57a4845b0da60a7b9f052160878097826320954affected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before cd17c5a1d9f186b57e9e2949be427803b7110a5caffected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before ac761e66708d51dac35c4c7f1891ea991dc788f0affected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before 628c63f96f4564fa145f602af2d41daf9532201faffected · git
    • 11da905412833d9b369a6a09a401f87149d674dc and later · before d3e91a95b2b0fc6336dbf3ec90d831a1654d2720affected · git
    • before 5.1not affected · semver

Package-level exposure

OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.

EcosystemPackageAffected rangeFix
Debian:12linuxbefore 6.1.187-16.1.187-1
Debian:13linuxbefore 6.12.100-16.12.100-1
Debian:14linuxbefore 7.1.5-17.1.5-1

Other highest-scoring records for the same primary product.

  • CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation
    40Plan
  • CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment
    40Plan
  • CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    40Plan
  • CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    40Plan
  • CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    40Plan
  • CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    40Plan

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

Product / packageFixed versionSource
Linux Linux616188becd4a208afbae1653fc5241e1748bae80Vendor (CNA)
Linux Linux628c63f96f4564fa145f602af2d41daf9532201fVendor (CNA)
Linux Linux89904b4f1dc0f9550c3f206dcdfceed0b7ce7c49Vendor (CNA)
Linux Linuxac761e66708d51dac35c4c7f1891ea991dc788f0Vendor (CNA)
Linux Linuxcd17c5a1d9f186b57e9e2949be427803b7110a5cVendor (CNA)
Linux Linuxd3b92d16e1c4debec7526b6dbb2d98d0aeed796bVendor (CNA)
Linux Linuxd3e91a95b2b0fc6336dbf3ec90d831a1654d2720Vendor (CNA)
Linux Linuxe57a4845b0da60a7b9f052160878097826320954Vendor (CNA)
debian:linux6.1.187-1 · Debian:12Package registry (OSV)

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

No commit or PR link among the references.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

No credits in the CNA record.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

No nightly-computed relations.

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

Technical details

No CVSS vector for this record, so attack conditions can't be derived.

Weakness class (CWE)

—

Attack context

MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.

MITRE has no CAPEC/ATT&CK mapping for this CWE.

Change log

  1. Fix✗ → ✓

For records you follow, these changes also arrive as notifications. →

References

All records