{"id":"CVE-2026-74733","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74733","summary":"gpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock\n\nLocking is disabled in the regmap config as this driver uses its own\nlock. This means that all calls to regmap functions (read or write) must\nhold the i2c_lock. The function pca953x_irq_bus_sync_unlock() did not do\nthis, and it was therefore possible that multiple threads could cause an\nincorrect register to be read/written.\n\nA previous patch partly fixed this, but only protected the write to the\ninterrupt mask register, and not the read from the direction register.","published":"2026-08-22T15:33:21.579Z","modified":"2026-08-24T11:47:22.284261027Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"7.1.9"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/9dc325327babe7f159e84cbe9380a45342da0585"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e6a2f5f845f50b0c4299bace5111f56d3390a090"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74733.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74733"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-24T11:47:22.284261027Z"}}