---
id: CVE-2026-98094
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  staging: fbtft: make dirty_lock IRQ-safe

  fbtft_mkdirty() can be reached from the fbcon rendering path while
  processing printk() in hardirq context
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  staging: fbtft: make dirty_lock IRQ-safe

  fbtft_mkdirty() can be reached from the fbcon rendering path while
  processing printk() in hardirq context. Meanwhile, dirty_lo…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= c296d5f9957c03994a699d6739c27d4581a9f6c7 <
    2a609e29efbba79f9abd68c4ec8a2bd7ecf291e7
  - >-
    Linux >= c296d5f9957c03994a699d6739c27d4581a9f6c7 <
    f0c869df2c33793c8828acaab3e4a5e0176f9f00
  - >-
    Linux >= c296d5f9957c03994a699d6739c27d4581a9f6c7 <
    dcb48fde8003492256dee45815144aa5ed26ce7c
  - >-
    Linux >= c296d5f9957c03994a699d6739c27d4581a9f6c7 <
    f576944a59f31bcffff121117ebf452c5dd162b7
  - Linux 4.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:39.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98094'
references:
  - url: 'https://git.kernel.org/stable/c/2a609e29efbba79f9abd68c4ec8a2bd7ecf291e7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dcb48fde8003492256dee45815144aa5ed26ce7c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f0c869df2c33793c8828acaab3e4a5e0176f9f00'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f576944a59f31bcffff121117ebf452c5dd162b7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.831Z'
epss: 0.00168
epssPercentile: 0.05403
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

staging: fbtft: make dirty_lock IRQ-safe

fbtft_mkdirty() can be reached from the fbcon rendering path while
processing printk() in hardirq context. Meanwhile, dirty_lock is also
taken by fbtft_deferred_io() in workqueue context with local interrupts
enabled.

Lockdep reports a possible IRQ lock inversion involving dirty_lock and
console_owner. A hardirq can interrupt a CPU holding dirty_lock and
enter the console rendering path, which can attempt to acquire
dirty_lock again.

The following lockdep report was observed on an RK3566 system with
CONFIG_PROVE_LOCKING enabled:

  WARNING: possible irq lock inversion dependency detected
  swapper/2/0 just changed the state of lock:
  (console_owner){-...}-{0:0}
  but this lock took another, HARDIRQ-unsafe lock in the past:
  (&par->dirty_lock){+.+.}-{2:2}

  CPU0                    CPU1
  ----                    ----
  lock(&par->dirty_lock);
                         local_irq_disable();
                         lock(console_owner);
                         lock(&par->dirty_lock);
  <Interrupt>
    lock(console_owner);

  *** DEADLOCK ***

Use spin_lock_irqsave() for fbtft_mkdirty() and spin_lock_irq() for
fbtft_deferred_io(). They only access the dirty line range, so the
IRQ-off regions remain short.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
