riscv: trace: fix snapshot deadlock with sbi ecall
Published Feb 18, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.08%
Description
If sbi_ecall.c's functions are traceable,
echo "__sbi_ecall:snapshot" > /sys/kernel/tracing/set_ftrace_filter
may get the kernel into a deadlock.
(Functions in sbi_ecall.c are excluded from tracing if CONFIG_RISCV_ALTERNATIVE_EARLY is set.)
__sbi_ecall triggers a snapshot of the ringbuffer. The snapshot code raises an IPI interrupt, which results in another call to __sbi_ecall and another snapshot...
All it takes to get into this endless loop is one initial __sbi_ecall. On RISC-V systems without SSTC extension, the clock events in timer-riscv.c issue periodic sbi ecalls, making the problem easy to trigger.
Always exclude the sbi_ecall.c functions from tracing to fix the potential deadlock.
sbi ecalls can easiliy be logged via trace events, excluding ecall functions from function tracing is not a big limitation.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version
-
- Version 6.10.10StatusaffectedConstraints<6.11
- Version
-
- Version 6.11StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.11
- Version 6.18.10StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.10.10 · < 6.11
- ≥ 6.11.1 · < 6.18.10
- 6.11
- 6.11
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-23217 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2440634 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-8018 Advisory
- https://git.kernel.org/stable/c/b0d7f5f0c9f05f1b6d4ee7110f15bef9c11f9df0 Patch
- https://git.kernel.org/stable/c/b1f8285bc8e3508c1fde23b5205f1270215d4984 Patch
- https://lore.kernel.org/linux-cve-announce/2026021800-CVE-2026-23217-f399@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-23217
- https://www.cve.org/CVERecord?id=CVE-2026-23217
Change history (0)
No recorded changes yet.