CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-80562

highCVSS 7.1covered by 3 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: gpio: ml-ioh: use raw_spinlock_t for the register lock ioh_irq_type() is registered as the irq_chip .irq_set_type callback and takes chip->spinlock with spin_lock_irqsave(). This callback is reached from __setup_irq() -> __irq_set_trigger() -> chip->irq_set_type() while the caller holds desc->lock, a raw_spinlock_t, with hardirqs disabled. That context is not sleepable, but on PREEMPT_RT a regular spinlock_t is an rtmutex-backed sleeping lock, so acquiring it there is invalid. ioh_irq_enable() and ioh_irq_disable() take the same lock from the .irq_enable/.irq_disable callbacks, which are likewise invoked with desc->lock held. Convert the register lock to raw_spinlock_t. The same lock also serializes the GPIO direction/value callbacks and the suspend/resume register save/restore, and those critical sections only perform short sequences of MMIO register accesses (ioread32()/iowrite32()); the .irq_set_type callback additionally emits a dev_warn() on an unsupported type. None of these are sleepable operations, so keeping this register lock non-sleeping is appropriate for the irqchip callbacks and does not change the GPIO-side locking contract. This is the same fix as commit a02b8950d619 ("gpio: pch: use raw_spinlock_t for the register lock"); this driver shares the same structure as gpio-pch.

CSIRTS triage

What
GPIO ml-ioh driver uses a non-raw spinlock for register access, risking race conditions and memory corruption.
Who is affected
Systems with Marvell OpenHCI GPIO driver enabled.
Urgency
High severity (CVSS 7.1) with no known active exploitation; patch promptly.
Action
Apply the kernel patch that converts the spinlock to raw_spinlock_t.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-80562

Get an email if CVE-2026-80562 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-80562

CVE.org record

Embed the live status

CVE-2026-80562 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-80562 status](https://www.csirts.com/badge/CVE-2026-80562)](https://www.csirts.com/cve/CVE-2026-80562)