CVE-2026-90124: irqchip/renesas-rzg2l: Fix loss of interrupt
In the Linux kernel, the following vulnerability has been resolved:
irqchip/renesas-rzg2l: Fix loss of interrupt
rzg2lclearirqint() and rzg2lcleartintint() perform a read-modify-write on the ISCR/TSCR status registers to clear the bit for the interrupt just handled. Since these registers are write-0-to-clear per bit, this is racy:
If another interrupt's status bit gets set between the read and the write, that bit is written back as 0 by the software-constructed value, clearing an interrupt that hasn't been serviced yet and losing it.
This can be reproduced by triggering multiple interrupts at once, e.g.:
gpioset -c gpiochip0 355=0 353=0 328=0 352=0
Fix this by writing back only the bit being cleared, with all other bits set to 1, instead of read-modify-writing the whole register. Since 1-bits are left unchanged by hardware, concurrently-set status bits for other interrupts are preserved.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux kernel Renesas RZ/G2L interrupt-controller driver are affected. The issue concerns the ISCR and TSCR interrupt status registers handled by that driver.
What is required to trigger the problem?
Multiple interrupts must be asserted close enough together for another status bit to be set between the driver's register read and write. The issue can be reproduced by triggering several GPIO interrupts at once.