Description
In the Linux kernel, the following vulnerability has been resolved:

pinctrl: airoha: add missed IRQ resource helpers

Without hooking .irq_request_resources, gpiolib cannot set
GPIOD_FLAG_USED_AS_IRQ. This breaks pin direction locking and can allow
userspace or another driver to reconfigure an active IRQ pin as an output
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via GPIO Pin Reconfiguration
Action: Apply Patch
AI Analysis

Impact

The vulnerability involves a missing hook for IRQ resource helpers in the Linux kernel’s airoha pinctrl driver. Because the .irq_request_resources method is not invoked, the framework fails to set the GPIOD_FLAG_USED_AS_IRQ flag. This oversight breaks the kernel’s pin direction locking mechanism, permitting userspace applications or other kernel modules to reconfigure an active IRQ pin as an output. This could be exploited to alter the electrical behavior of the hardware, potentially disabling interrupts or causing unexpected data flows, which provides avenues for privilege escalation or denial of service.

Affected Systems

This flaw affects the Linux kernel itself. The affected vendor/product list reads Linux:Linux twice; version specifics are not disclosed, so any kernel build that includes the airoha pinctrl driver is potentially impacted until patched.

Risk and Exploitability

The EPSS score indicates a very low exploitation probability (<1%) and the vulnerability is not listed in CISA’s KEV catalog. No CVSS figure is supplied, but the defect grants the ability to reconfigure critical hardware lines, which is a high‑severity impact if an attacker can reach a privileged context. The likelihood of an attack relies on successfully exploiting the missing flag; from the description it is inferred that the attacker must have the ability to load an alternate kernel module or invoke a driver that manipulates the IRQ pin. As the attack vector is internal to the kernel, only privileged users or compromised drivers can trigger it, reducing the exposure to low‑level. Nonetheless the potential impact warrants close attention.

Generated by OpenCVE AI on September 19, 2026 at 03:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the patch for the airoha pinctrl driver
  • Reboot the system to load the updated kernel and driver
  • If an immediate kernel upgrade is unavailable, disable the airoha driver or remove the affected pin entries from the device tree to prevent the pins from being used as IRQ
  • Monitor kernel logs for attempts to reconfigure IRQ pins and apply any future vendor patches as soon as they are released

Generated by OpenCVE AI on September 19, 2026 at 03:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pinctrl: airoha: add missed IRQ resource helpers Without hooking .irq_request_resources, gpiolib cannot set GPIOD_FLAG_USED_AS_IRQ. This breaks pin direction locking and can allow userspace or another driver to reconfigure an active IRQ pin as an output
Title pinctrl: airoha: add missed IRQ resource helpers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:56.730Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.220

Modified: 2026-09-17T17:17:22.220

Link: CVE-2026-90258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:15:13Z

Weaknesses
  • CWE-20

    Improper Input Validation