CVE-2026-63977

Summary

In the Linux kernel, the following vulnerability has been resolved:

dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work

The change_work was introduced to send device change notifications from DPLL device callbacks without deadlocking on dpll_lock, since the callbacks are already invoked under that lock. Now that __dpll_device_change_ntf() is exported for callers that already hold dpll_lock, use it directly and remove the change_work infrastructure entirely.

This eliminates a race condition where change_work could be re-scheduled after cancel_work_sync() during device teardown, potentially causing the handler to dereference a freed or NULL dpll_dev pointer.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux9363b4837659d1b7ee04cfa714373ce4b4b8269f < e7a33807fb3f87a855993474ac21684ce105927baffected
LinuxLinux9363b4837659d1b7ee04cfa714373ce4b4b8269f < d733f519f6443540f8359461a34e3b0042099bbeaffected
LinuxLinux6.18affected
LinuxLinux0 < 6.18unaffected
LinuxLinux7.0.12 <= 7.0.*unaffected
LinuxLinux7.1 <= *unaffected

Weaknesses

References