Linux Kernel Ethernet Driver Vulnerability Affecting ARC EMAC
CVE-2026-64587

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64587?

A vulnerability in the ARC EMAC driver of the Linux kernel relates to improper interrupt handling that may allow stale or latched interrupt statuses, potentially left by firmware or bootloaders, to disrupt normal operations. The driver can receive unexpected interrupts when the device is not properly configured, which could lead to conditions that compromise system stability and reliability. To mitigate this issue, it's crucial to quiesce the device before requesting IRQs, ensuring that all EMAC interrupt sources are disabled and any pending interrupt status bits are cleared. This approach minimizes the risk of spurious IRQ deliveries and enhances the robustness of the driver's interaction with network devices.

Affected Version(s)

Linux e4f2379db6c6823c5d4a4c2c912df00c65de51d7

Linux e4f2379db6c6823c5d4a4c2c912df00c65de51d7 < 5f29dd540fe5ea3c826fc8ec759ba488b31f9707

Linux e4f2379db6c6823c5d4a4c2c912df00c65de51d7 < 6fc7449773748c7b904235a09a67054d78ab1172

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.