net: lan743x: Initialize eth_syslock spinlock before use

Summary

CVECVE-2026-72037
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-15 06:21:12 UTC
Updated2026-08-15 06:21:12 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: lan743x: Initialize eth_syslock spinlock before use lan743x_hardware_init() calls pci11x1x_strap_get_status() during the PCI11x1x probe sequence. That helper acquires the Ethernet subsystem hardware lock via lan743x_hs_syslock_acquire(), which relies on adapter->eth_syslock_spinlock to serialize access. The spinlock is currently initialized only after the strap status is read. With CONFIG_DEBUG_SPINLOCK enabled, taking the zeroed initialized spinlock can trip the spinlock debug check. Fix by initializing adapter->eth_syslock_spinlock before reading the strap status so the probe path never attempts to lock an uninitialized spinlock.

Risk And Classification

EPSS: 0.002050000 probability, percentile 0.108570000 (date 2026-08-15)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 dfaefd9a7808736fcd2ed0de108f55c4badc15cc git Not specified
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 6523daa6852b1bfef32ec7a105b0217e8a115687 git Not specified
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 b6a93a42e0e61f0ba0005a942ee3bffb16c0574e git Not specified
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 99a6f37b113c46815deb160c5012073563679ef4 git Not specified
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 b99e890e6b32ffa11c145a16fefcf2c7137a9578 git Not specified
CNA Linux Linux affected 46b777ad9a8c269113634cee6a380bc4e53f3964 39139b1c1c2b614096519b526112c726adb12ff0 git Not specified
CNA Linux Linux affected 6.0 Not specified
CNA Linux Linux unaffected 6.0 semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.40 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.5 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/b6a93a42e0e61f0ba0005a942ee3bffb16c0574e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/99a6f37b113c46815deb160c5012073563679ef4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/39139b1c1c2b614096519b526112c726adb12ff0 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/6523daa6852b1bfef32ec7a105b0217e8a115687 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/dfaefd9a7808736fcd2ed0de108f55c4badc15cc 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b99e890e6b32ffa11c145a16fefcf2c7137a9578 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report