net: lan743x: Initialize eth_syslock spinlock before use
Summary
| CVE | CVE-2026-72037 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-15 06:21:12 UTC |
| Updated | 2026-08-15 06:21:12 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Initialize eth_syslock spinlock before use lan743x_hardware_init() calls pci11x1x_strap_get_status() during the PCI11x1x probe sequence. That helper acquires the Ethernet subsystem hardware lock via lan743x_hs_syslock_acquire(), which relies on adapter->eth_syslock_spinlock to serialize access. The spinlock is currently initialized only after the strap status is read. With CONFIG_DEBUG_SPINLOCK enabled, taking the zeroed initialized spinlock can trip the spinlock debug check. Fix by initializing adapter->eth_syslock_spinlock before reading the strap status so the probe path never attempts to lock an uninitialized spinlock. |
Risk And Classification
EPSS: 0.002050000 probability, percentile 0.108570000 (date 2026-08-15)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 dfaefd9a7808736fcd2ed0de108f55c4badc15cc git | Not specified |
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 6523daa6852b1bfef32ec7a105b0217e8a115687 git | Not specified |
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 b6a93a42e0e61f0ba0005a942ee3bffb16c0574e git | Not specified |
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 99a6f37b113c46815deb160c5012073563679ef4 git | Not specified |
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 b99e890e6b32ffa11c145a16fefcf2c7137a9578 git | Not specified |
| CNA | Linux | Linux | affected 46b777ad9a8c269113634cee6a380bc4e53f3964 39139b1c1c2b614096519b526112c726adb12ff0 git | Not specified |
| CNA | Linux | Linux | affected 6.0 | Not specified |
| CNA | Linux | Linux | unaffected 6.0 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.178 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.145 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.97 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.40 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.5 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2-rc2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/b6a93a42e0e61f0ba0005a942ee3bffb16c0574e | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/99a6f37b113c46815deb160c5012073563679ef4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/39139b1c1c2b614096519b526112c726adb12ff0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6523daa6852b1bfef32ec7a105b0217e8a115687 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/dfaefd9a7808736fcd2ed0de108f55c4badc15cc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b99e890e6b32ffa11c145a16fefcf2c7137a9578 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.