Description
In the Linux kernel, the following vulnerability has been resolved:

pinctrl: mediatek: free EINT resources on unbind

mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for
every EINT line and installs a chained handler on the parent interrupt,
but none of these are ever released. This was harmless while the drivers
were built-in, but now that they can be built as modules and
unbound/rmmod'd it leaves behind a dangling IRQ domain, interrupt mappings
whose chip data points at freed memory, and a chained handler that keeps
firing into that freed data.

The plain allocations in mtk_eint_do_init() already use the device-managed
devm_*() helpers, so tear the remaining resources down the same way:
register a devm action that detaches the chained handler, waits for any
in-flight handler to finish, disposes of the per-line mappings and removes
the IRQ domain. This mirrors the device-managed lifecycle adopted for the
GPIO chip and keeps the whole EINT setup self-cleaning on unbind.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The Mediatek pinctrl driver allocates an IRQ domain and installs a chained interrupt handler during initialization, but never releases those allocations when the driver is unbound or removed. This oversight results in a dangling IRQ domain, invalid interrupt mappings pointing to freed memory, and a chained handler that continues to fire into corrupted objects. The consequence is a use‑after‑free scenario that can trigger a kernel crash or, if an attacker can induce the stale interrupts, facilitate arbitrary code execution at elevated privileges.

Affected Systems

Any Linux kernel that incorporates the Mediatek pinctrl driver, either built into the kernel or loaded as a module, is susceptible. The data set does not list specific kernel versions, so vulnerability likely affects all builds containing the affected driver code until patched.

Risk and Exploitability

The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation probability. However, the high impact of a kernel use‑after‑free, combined with the ability for privileged users to unload the driver, makes this a serious risk when the kernel is exposed to untrusted code. The likely attack vector involves a privileged user loading and unloading the driver while generating EINT events, but the attack requires local root or equivalent access.

Generated by OpenCVE AI on September 19, 2026 at 05:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel patch that frees all EINT resources on driver unbind as described in the fix.
  • If a patch is unavailable, build Mediatek drivers into the kernel rather than as loadable modules to eliminate the unbind path that creates dangling resources.
  • Before unloading the driver, disable EINT sources or clear pending interrupts through sysfs or other kernel interfaces to prevent stray interrupts from reaching the freed context.

Generated by OpenCVE AI on September 19, 2026 at 05:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: free EINT resources on unbind mtk_eint_do_init() creates an IRQ domain, populates it with a mapping for every EINT line and installs a chained handler on the parent interrupt, but none of these are ever released. This was harmless while the drivers were built-in, but now that they can be built as modules and unbound/rmmod'd it leaves behind a dangling IRQ domain, interrupt mappings whose chip data points at freed memory, and a chained handler that keeps firing into that freed data. The plain allocations in mtk_eint_do_init() already use the device-managed devm_*() helpers, so tear the remaining resources down the same way: register a devm action that detaches the chained handler, waits for any in-flight handler to finish, disposes of the per-line mappings and removes the IRQ domain. This mirrors the device-managed lifecycle adopted for the GPIO chip and keeps the whole EINT setup self-cleaning on unbind.
Title pinctrl: mediatek: free EINT resources on unbind
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:58.378Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92481

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.153

Modified: 2026-09-17T17:17:50.153

Link: CVE-2026-92481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T09:30:13Z

Weaknesses