Description
In the Linux kernel, the following vulnerability has been resolved:

clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path

When cpuhp_setup_state fails after pit_clockevent_per_cpu_init has
successfully called request_irq, the error handling jumps directly to
out_pit_clocksource_unregister without freeing the registered IRQ.

This leaks the IRQ line and, since kfree(pit) follows, leaves a
dangling pointer registered as the interrupt handler's dev_id,
potentially leading to a use-after-free if the IRQ fires afterwards.

Fix it by calling pit_clockevent_per_cpu_exit to properly release the
IRQ before falling through to the existing cleanup chain.
Published: 2026-09-11
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free
Action: Patch
AI Analysis

Impact

The vulnerability resides in the Linux kernel’s NXP PIT clocksource driver. If cpuhp_setup_state fails after request_irq has be successfully called, the path skips the IRQ release step and jumps directly to unregistration logic, leaving the IRQ line registered but not freed. The interrupt handler’s dev_id then points to a structure that is freed, subsequent interrupt on that IRQ would dereference the stale pointer, resulting in a use‑after‑free that an attacker could potentially exploit to gain arbitrary code execution in the kernel. This flaw is identified as CWE‑825, an improper resource release leading to a use‑after‑free.

Affected Systems

All Linux kernel configurations that include the nxp_pit driver and enable it during boot or CPU hotplug are susceptible. Any kernel build that lacks the recent commit fixing the cleanup path is vulnerable, regardless of kernel version, as the issue is present in the mainline code base until the patch is applied.

Risk and Exploitability

The flaw is classified as high severity, while the EPSS score of <1% indicates a very low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need local privilege and the ability to trigger a failure in cpuhp_setup_state, such as by manipulating CPU hotplug or inducing a setup failure, and then generate an interrupt on the leaked IRQ after the driver structure has been freed. No publicly available exploits are documented, but the combination of a serious impact and potential for privilege escalation warrants timely remediation. This flaw maps to CWE‑825, indicating a resource release error that can lead to use‑after‑free.

Generated by OpenCVE AI on September 15, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes commit 05520e035f8332c8e33f3011b5ca016fde61793d or later, which ensures proper IRQ release on failure.
  • If kernel upgrade is not possible, disable the NX‑PIT driver by adding "blacklist nxp_pit" to /etc/modprobe.d/ executed.
  • When unloading the driver manually, make sure pit_clockevent_per_cpu_exit is called before the framework cleans up the driver to guarantee the IRQ is released correctly.

Generated by OpenCVE AI on September 15, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path When cpuhp_setup_state fails after pit_clockevent_per_cpu_init has successfully called request_irq, the error handling jumps directly to out_pit_clocksource_unregister without freeing the registered IRQ. This leaks the IRQ line and, since kfree(pit) follows, leaves a dangling pointer registered as the interrupt handler's dev_id, potentially leading to a use-after-free if the IRQ fires afterwards. Fix it by calling pit_clockevent_per_cpu_exit to properly release the IRQ before falling through to the existing cleanup chain.
Title clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_setup_state error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:34:11.282Z

Reserved: 2026-09-11T19:38:34.765Z

Link: CVE-2026-89769

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:08.240

Modified: 2026-09-13T07:17:41.190

Link: CVE-2026-89769

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:47:08Z

Links: CVE-2026-89769 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference