{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  net: sparx5: fix sleep in atomic context in MAC table access  sparx5_set_rx_mode() runs with netif_addr_lock_bh held and iterates dev-\u003emc via __dev_mc_sync(), which per address calls sparx5_mc_sync() / sparx5_mc_unsync() -\u003e sparx5_mact_learn() / sparx5_mact_forget().  These take sparx5-\u003elock, a mutex, and then poll the MAC access command register with readx_poll_timeout(). A mutex may block, which is not allowed from atomic context.  Convert the driver to the new .ndo_set_rx_mode_async callback introduced in commit 3554b4345d85 (\"net: introduce ndo_set_rx_mode_async and netdev_rx_mode_work\"). The async callback is invoked from process context, so the mutex and sleeping completion poll can remain.  Observed with CONFIG_PROVE_LOCKING, CONFIG_DEBUG_SPINLOCK, CONFIG_DEBUG_MUTEXES and CONFIG_DEBUG_ATOMIC_SLEEP enabled:    BUG: sleeping function called from invalid context at kernel/locking/mutex.c:591   in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 217, name: ip   preempt_count: 201, expected: 0   Call trace:    __might_resched+0x144/0x248    __might_sleep+0x48/0x7c    __mutex_lock+0x74/0x850    mutex_lock_nested+0x24/0x30    sparx5_mact_learn+0x78/0x100    sparx5_mc_sync+0x40/0x54    __hw_addr_sync_dev+0xc4/0x170    sparx5_set_rx_mode+0x4c/0x58    __dev_set_rx_mode+0x64/0xa4    __dev_open+0x1ec/0x26c",
  "id": "DEBIAN-CVE-2026-90098",
  "modified": "2026-09-18T04:47:31.410728239Z",
  "published": "2026-09-17T17:17:01.460Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90098"
    }
  ],
  "upstream": [
    "CVE-2026-90098"
  ]
}