Answer in brief
CVE-2026-89945 records a Unknown severity vulnerability in ASoC: cs35l34: drain threaded IRQ before runtime suspend. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <3be8380fb14d602cd833e5852e6d83c1e7eb1ceb || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <96982734e765c13c3db02067e1d5784682085f5c || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <5b063739619990d5de0c94c85d6e5be14e7cbdfe || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <f4bfd755c52dfa7584e6c9374206b71b8895c997 || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <4fe8a91a9266f1321c2d31ce67940a4e8b93559e || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <5a4fe7a87841af23ba80bae31b80355b16926cf4 || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <07a86575edc308e66b6c8873ed4a93ef3a063e55 || >=c1124c09e1035cabdbc17d4538ae6f922086fec9 <4105a4c0678b2808fc8046b60321b4f1cc7dae75 | 3be8380fb14d602cd833e5852e6d83c1e7eb1ceb, 96982734e765c13c3db02067e1d5784682085f5c, 5b063739619990d5de0c94c85d6e5be14e7cbdfe, f4bfd755c52dfa7584e6c9374206b71b8895c997, 4fe8a91a9266f1321c2d31ce67940a4e8b93559e, 5a4fe7a87841af23ba80bae31b80355b16926cf4, 07a86575edc308e66b6c8873ed4a93ef3a063e55, 4105a4c0678b2808fc8046b60321b4f1cc7dae75 |
| Linux/Linuxgeneric | 4.10 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: ASoC: cs35l34: drain threaded IRQ before runtime suspend cs35l34_runtime_suspend() currently switches the codec into regcache_cache_only(true), asserts reset low, and powers the device off without first quiescing the threaded IRQ registered by devm_request_threaded_irq(). That leaves a window where cs35l34_irq_thread() can still run after suspend has removed live hardware access. A running system can reach this during runtime PM while the driver still has critical fault IRQs unmasked. If the threaded handler runs in that window, it reads volatile INT_STATUS_1..4 after cache_only has been enabled, ignores the regmap_read() failures, and can still execute the PROT_RELEASE_CTL release sequence or the BST fault power-down writes. Use disable_irq() before entering cache_only/reset-low/power-off so any in-flight threaded handler is drained and no new IRQ thread can run while the device is suspended. Re-enable the IRQ only after runtime_resume() has restored live register access with regcache_sync(). Since probe only logs request_threaded_irq() failures and keeps going, track whether the IRQ was actually installed before disabling or re-enabling it.
Quoted source text, attributed separately from HOL analysis.