{"id":"CVE-2026-80930","title":"kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (CVE-2026-80930)","summary":"A flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The `i2c_nuvoton_wait_for_stat()` function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an u…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-772","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","affected":["enterprise_linux 10","enterprise_linux 7","enterprise_linux 8","enterprise_linux 9","openshift_container_platform 4"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T13:54:47+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80930.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80930.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80930"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532134"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80930"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80930"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80930.mbox"},{"url":"https://git.kernel.org/stable/c/007c9e637e0e0b9d946b7f0e8a42f1f1aca48d7a"},{"url":"https://git.kernel.org/stable/c/2c9147b2c0d75091ab451c2461d1c91788a7e60b"},{"url":"https://git.kernel.org/stable/c/07c2544a47da481043e945322b1bef71cdd7af79"},{"url":"https://git.kernel.org/stable/c/b0dc3f18af01ba9f157b7d810cb22d3752d244ef"},{"url":"https://git.kernel.org/stable/c/73e89faee1f9b9119fa70b679058b045168ae633"},{"url":"https://git.kernel.org/stable/c/cde2d927c29e82380851f209222256c607969a1f"},{"url":"https://git.kernel.org/stable/c/aee2296d09f6aeff41db369c6fd2dcaea3ee302c"},{"url":"https://git.kernel.org/stable/c/705c4ed0643366963547b2616d53165f2519c81f"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00176,"epssPercentile":0.07438,"ingestedAt":"2026-09-14T15:23:07.455Z","slug":"CVE-2026-80930","body":"## Overview\n\nA flaw was found in the Linux kernel's TPM I2C Nuvoton driver. The `i2c_nuvoton_wait_for_stat()` function enables an interrupt (IRQ) but fails to disable it if the wait operation times out or is interrupted. This oversight can lead to an unbalanced IRQ state, potentially causing system instability or resource exhaustion, which could result in a Denial of Service (DoS).\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, … · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80930.json)\n\n**kernel: tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":202775,"id":"CVE-2026-80930","ts":1789403715849,"field":"cvss","old":null,"new":"5.5"},{"seq":202774,"id":"CVE-2026-80930","ts":1789403715849,"field":"severity","old":"none","new":"medium"},{"seq":147690,"id":"CVE-2026-80930","ts":1789270211897,"field":"cvss","old":null,"new":"4.1"},{"seq":147689,"id":"CVE-2026-80930","ts":1789270211897,"field":"severity","old":"none","new":"medium"},{"seq":109446,"id":"CVE-2026-80930","ts":1789183731945,"field":"cvss","old":null,"new":"4.1"},{"seq":109445,"id":"CVE-2026-80930","ts":1789183731945,"field":"severity","old":"none","new":"medium"}]}