---
cve: "CVE-2026-23217"
severity: "LOW"
cvss: 3.1
epss: "8%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-02-18 15:18:43"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T21:11:40+02:00"
---

# CVE-2026-23217

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

riscv: trace: fix snapshot deadlock with sbi ecall

If sbi_ecall.c's functions are traceable,

echo "__sbi_ecall:snapshot" > /sys/kernel/tracing/set_ftrace_filter

may get the kernel into a deadlock.

(Functions in sbi_ecall.c are excluded from tracing if
CONFIG_RISCV_ALTERNATIVE_EARLY is set.)

__sbi_ecall triggers a snapshot of the ringbuffer. The snapshot code
raises an IPI interrupt, which results in another call to __sbi_ecall
and another snapshot...

All it takes to get into this endless loop is one initial __sbi_ecall.
On RISC-V systems without SSTC extension, the clock events in
timer-riscv.c issue periodic sbi ecalls, making the problem easy to
trigger.

Always exclude the sbi_ecall.c functions from tracing to fix the
potential deadlock.

sbi ecalls can easiliy be logged via trace events, excluding ecall
functions from function tracing is not a big limitation.

## Patch verfügbar (OSV)

- Kernel ≥ 6.18.10

## Referenzen

- <https://git.kernel.org/stable/c/b1f8285bc8e3508c1fde23b5205f1270215d4984>
- <https://git.kernel.org/stable/c/b0d7f5f0c9f05f1b6d4ee7110f15bef9c11f9df0>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-23217) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
