Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remoteproc starts in parallel with the NGD driver being probed, or the remoteproc is already up when the PDR lookup is being registered, or in the theoretical event that we get an interrupt from the hardware, these callbacks will operate on uninitialized data. This result in issues to boot the affected boards. One such example can be seen in the following fault, where qcom_slim_ngd_ssr_pdr_notify() schedules work on the NULL ngd_up_work. [ 21.858578] ------------[ cut here ]------------ [ 21.858745] WARNING: kernel/workqueue.c:2338 at __queue_work+0x5e0/0x790, CPU#2: kworker/2:2/116 ... [ 21.859251] Call trace: [ 21.859255] __queue_work+0x5e0/0x790 (P) [ 21.859265] queue_work_on+0x6c/0xf0 [ 21.859273] qcom_slim_ngd_ssr_pdr_notify+0x110/0x150 [slim_qcom_ngd_ctrl] [ 21.859304] qcom_slim_ngd_ssr_notify+0x24/0x40 [slim_qcom_ngd_ctrl] [ 21.859318] notifier_call_chain+0xa4/0x230 [ 21.859329] srcu_notifier_call_chain+0x64/0xb8 [ 21.859338] ssr_notify_start+0x40/0x78 [qcom_common] [ 21.859355] rproc_start+0x130/0x230 [ 21.859367] rproc_boot+0x3d4/0x518 ... Move the enablement of interrupts, and the registration of SSR and PDR until after the NGD device has been registered. This could be further refined by moving initialization to the control driver probe and by removing the platform driver model from the picture.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.19, < 5.10.260 |
References
- https://git.kernel.org/stable/c/08564e15c47a5fb0af6643a43ee15521d49bcdeaPatch
- https://git.kernel.org/stable/c/2047eeb38db878a31f58db19d98f8aedf284342e
- https://git.kernel.org/stable/c/24ec89123fc9d0d24ce719dcf7fd6c57e5b0d753Patch
- https://git.kernel.org/stable/c/290014c7987636e6105bba89fa04cb4d59f775c1
- https://git.kernel.org/stable/c/2a9d50e9ea406e0c8735938484adc20515ef1b47Patch
- https://git.kernel.org/stable/c/946b97d632f0f58a705dafac644c1e9346e01f35Patch
- https://git.kernel.org/stable/c/afc631e246936a40558f494112a4188401382671
- https://git.kernel.org/stable/c/fa3790c7ea98328ddc3f7d8bf40247556245a6fcPatch
FAQ
What is CVE-2026-53332?
CVE-2026-53332 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remoteproc starts in parallel with the NGD driver being...
How severe is CVE-2026-53332?
CVE-2026-53332 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-53332?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.