{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO  rtl83xx_reset_assert() and rtl83xx_reset_deassert() are only called from the probe path, which may sleep and is not timing-critical.  When the reset GPIO is provided by a sleeping controller such as an I2C I/O expander, gpiod_set_value() warns:    WARNING: drivers/gpio/gpiolib.c:4030 at gpiod_set_value+0x44/0x80, CPU#1: kworker/u16:4/61   Hardware name: B\u0026O MAP CA33 Rev f (UNKNOWN) (DT)   Workqueue: events_unbound deferred_probe_work_func   pc : gpiod_set_value+0x44/0x80   lr : rtl83xx_probe+0x1d8/0x3a0   Call trace:    gpiod_set_value+0x44/0x80 (P)    rtl83xx_probe+0x1d8/0x3a0    realtek_mdio_probe+0x24/0xa0    mdio_probe+0x38/0x78    really_probe+0xc4/0x3e0    __driver_probe_device+0x15c/0x1b8    driver_probe_device+0xb4/0x120    __device_attach_driver+0xb8/0x1a0    bus_for_each_drv+0x88/0xf0    __device_attach+0xa0/0x1d8    device_initial_probe+0x54/0x68    bus_probe_device+0x38/0xa0    deferred_probe_work_func+0xb8/0x120    process_one_work+0x184/0x4e8    worker_thread+0x188/0x308    kthread+0x130/0x150    ret_from_fork+0x10/0x20  Switch both helpers to gpiod_set_value_cansleep() so such a reset GPIO can be used without triggering the warning.  The reset GPIO has been driven with the non-sleeping gpiod_set_value() since the driver was added in v4.19.  The call has since been refactored across several files - from realtek-smi.c / realtek-mdio.c into the common rtl83xx.c module and then into the rtl83xx_reset_assert() and rtl83xx_reset_deassert() helpers (both in v6.9).  This patch therefore applies as-is only to kernels that carry those helpers (v6.9+); older stable kernels need the same gpiod_set_value_cansleep() conversion at the corresponding open-coded call sites.",
  "id": "DEBIAN-CVE-2026-80999",
  "modified": "2026-09-12T08:47:27.565309839Z",
  "published": "2026-09-11T20:19:07.433Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80999"
    }
  ],
  "upstream": [
    "CVE-2026-80999"
  ]
}