---
id: CVE-2026-90193
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

  qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding
  chan->lock
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

  qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding
  chan->lock. Under PREEMPT_RT, s…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0e2a9a03106cd5fa0dbc9047675e7645c55e2669 <
    aa482273f32117c3adeba9b1cc945e0b5d33722d
  - >-
    Linux >= 0e2a9a03106cd5fa0dbc9047675e7645c55e2669 <
    8b8de6400c86937ed57d680d06d716e167b381de
  - >-
    Linux >= 0e2a9a03106cd5fa0dbc9047675e7645c55e2669 <
    e40b3edeaf25cd09e9c88edb1ef99373ca37593b
  - >-
    Linux >= 0e2a9a03106cd5fa0dbc9047675e7645c55e2669 <
    3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c
  - Linux 6.11
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:14.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90193'
references:
  - url: 'https://git.kernel.org/stable/c/3690aaa6d18f6775c3e7932fb8af8c5bf6a6b69c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8b8de6400c86937ed57d680d06d716e167b381de'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/aa482273f32117c3adeba9b1cc945e0b5d33722d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e40b3edeaf25cd09e9c88edb1ef99373ca37593b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.862Z'
epss: 0.00209
epssPercentile: 0.09788
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler

qcom_cpucp_mbox_irq_fn() calls mbox_chan_received_data() while holding
chan->lock. Under PREEMPT_RT, spin_lock_irqsave() is converted to an
rt_spinlock (rtmutex-based), which tracks ownership and can sleep.

The callback chain triggered by mbox_chan_received_data() eventually
reaches mailbox_clear_channel() -> mbox_send_message() -> add_to_rbuf(),
which attempts to re-acquire the same chan->lock. Since rtmutex detects
the re-entrant lock attempt by the same owner, the thread blocks waiting
for a lock it already holds, causing a permanent deadlock.

This deadlock manifests as 'irq/N-apss_cpucp_mbox' stuck in D state
with the following call trace:
  rt_spin_lock -> mbox_send_message -> mailbox_clear_channel ->
  scmi_rx_callback -> mbox_chan_received_data [<- held chan->lock here]

Fix by saving chan->cl locally and clearing the HW interrupt register
inside the lock, then invoking mbox_chan_received_data() after releasing
the lock. This preserves the mutual exclusion for chan->cl access while
avoiding the lock re-entrancy that causes the PREEMPT_RT deadlock.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
