Impact
The Mediatek pinctrl driver allocates an IRQ domain and installs a chained interrupt handler during initialization, but never releases those allocations when the driver is unbound or removed. This oversight results in a dangling IRQ domain, invalid interrupt mappings pointing to freed memory, and a chained handler that continues to fire into corrupted objects. The consequence is a use‑after‑free scenario that can trigger a kernel crash or, if an attacker can induce the stale interrupts, facilitate arbitrary code execution at elevated privileges.
Affected Systems
Any Linux kernel that incorporates the Mediatek pinctrl driver, either built into the kernel or loaded as a module, is susceptible. The data set does not list specific kernel versions, so vulnerability likely affects all builds containing the affected driver code until patched.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation probability. However, the high impact of a kernel use‑after‑free, combined with the ability for privileged users to unload the driver, makes this a serious risk when the kernel is exposed to untrusted code. The likely attack vector involves a privileged user loading and unloading the driver while generating EINT events, but the attack requires local root or equivalent access.
OpenCVE Enrichment
Debian DLA
Debian DSA