Description
In the Linux kernel, the following vulnerability has been resolved:

irqchip/gic-v5: Clear per-CPU IRS data on teardown

IRS affinity setup publishes an IRS pointer and IAFFID state in the
per-CPU data before the remaining IRS initialization can fail. The
error path then frees the IRS data without clearing that published
state, leaving CPUs associated with freed memory.

On initialization failure and normal IRS teardown, clear the per-CPU
IRS association by removing the stale pointer to irs_data. Also
invalidate the per-CPU IAFFID state for any CPUs that were tied to the
IRS before it was freed.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to memory corruption
Action: Patch immediately
AI Analysis

Impact

During the initialization or teardown of the Generic Interrupt Controller version 5, per-CPU data was left pointing to IRS structures that had been freed because the error path did not clear the published pointers and IAFFID state. The stale pointers could be dereferenced by the kernel after the memory reclamation, creating a classic use‑after‑free scenario that may result in arbitrary memory corruption or in the worst case code execution. The failure occurs before the IRS subsystem becomes fully functional, so a corrupted pointer can be accessed very early in kernel execution.

Affected Systems

The flaw affects the Linux kernel, specifically any build that implements the GIC v5 IRQ chip with IRS support. No specific kernel version numbers are listed, but the issue exists in any kernel that has not applied the two referenced patches. Users of the official Linux kernel releases prior to incorporating the commits cited in the references are therefore exposed.

Risk and Exploitability

The EPSS score is under 1%, indicating a low likelihood of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. However, because a use‑after‑free in the kernel can allow an attacker with local or elevated privileges to corrupt memory or gain code execution, the potential impact is high. The attack vector is inferred to be local with kernel privileges, as the flaw resides inside the interrupt controller driver and requires that the affected kernel code be loaded.

Generated by OpenCVE AI on September 20, 2026 at 02:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Linux kernel patch that includes commits 3dfc0ab5fefd052c6028c4632b1fad8bdaf7967e or 54937af6f4a0d44c2852a203d457902f3264c906, ensuring the IRS per‑CPU data is cleared on teardown.
  • If immediate kernel upgrade is not possible, reconfigure the system to avoid using the GIC v5 IRQ chip or disable IRS functionality to prevent dangling pointer usage.
  • Monitor system logs and kernel crash dumps for signs of memory corruption or panics that could indicate exploitation of the stale pointers.

Generated by OpenCVE AI on September 20, 2026 at 02:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v5: Clear per-CPU IRS data on teardown IRS affinity setup publishes an IRS pointer and IAFFID state in the per-CPU data before the remaining IRS initialization can fail. The error path then frees the IRS data without clearing that published state, leaving CPUs associated with freed memory. On initialization failure and normal IRS teardown, clear the per-CPU IRS association by removing the stale pointer to irs_data. Also invalidate the per-CPU IAFFID state for any CPUs that were tied to the IRS before it was freed.
Title irqchip/gic-v5: Clear per-CPU IRS data on teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:25.253Z

Reserved: 2026-09-11T19:38:34.787Z

Link: CVE-2026-90121

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:04.310

Modified: 2026-09-17T17:17:04.310

Link: CVE-2026-90121

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:11Z

Weaknesses