Impact
During the initialization or teardown of the Generic Interrupt Controller version 5, per-CPU data was left pointing to IRS structures that had been freed because the error path did not clear the published pointers and IAFFID state. The stale pointers could be dereferenced by the kernel after the memory reclamation, creating a classic use‑after‑free scenario that may result in arbitrary memory corruption or in the worst case code execution. The failure occurs before the IRS subsystem becomes fully functional, so a corrupted pointer can be accessed very early in kernel execution.
Affected Systems
The flaw affects the Linux kernel, specifically any build that implements the GIC v5 IRQ chip with IRS support. No specific kernel version numbers are listed, but the issue exists in any kernel that has not applied the two referenced patches. Users of the official Linux kernel releases prior to incorporating the commits cited in the references are therefore exposed.
Risk and Exploitability
The EPSS score is under 1%, indicating a low likelihood of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. However, because a use‑after‑free in the kernel can allow an attacker with local or elevated privileges to corrupt memory or gain code execution, the potential impact is high. The attack vector is inferred to be local with kernel privileges, as the flaw resides inside the interrupt controller driver and requires that the affected kernel code be loaded.
OpenCVE Enrichment