CVE-2026-64238 is a vulnerability in Linux Kernel
Published on July 24, 2026
gpio: shared: fix deadlock on shared proxy's parent removal
In the Linux kernel, the following vulnerability has been resolved:
gpio: shared: fix deadlock on shared proxy's parent removal
Commit 710abda58055 ("gpio: shared: call gpio_chip::of_xlate() if set")
used the mutex embedded in struct gpio_shared_entry to protect the
offset field which now can be modified after assignment. The critical
section however is too wide and introduced a potential deadlock on the
removal of the shared GPIO proxy's parent.
Make the critical section shorter - only protect the offset when it's
being read.
While at it: mention the fact that the entry lock is now also used to
protect against concurrent access to the offset field in the structure's
documentation.
Products Associated with CVE-2026-64238
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 710abda58055ed5eaa8958107633cc12a365c328 and below a554dfcd30dd5e41d1d67387b3bb85cea83e12e1 is affected.
- Version 710abda58055ed5eaa8958107633cc12a365c328 and below a1b836607304f71051f9f9dcccf8b5097b86a1fb is affected.
- Version 28f488e7b327630686378bb1d24e22cfc3fc162d is affected.
- Version 6.19.12 and below 6.20 is affected.
- Version 7.0 is affected.
- Before 7.0 is unaffected.
- Version 7.0.12, <= 7.0.* is unaffected.
- Version 7.1, <= * is unaffected.