Description
In the Linux kernel, the following vulnerability has been resolved:

pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip

The gpio_chip is allocated with device-managed memory but registered with
the non-managed gpiochip_add_data(). This was harmless while the drivers
were built-in, but once they can be built as modules and unbound/rmmod'd,
devm frees the gpio_chip's memory while it is still registered, causing a
use-after-free.

Register it with devm_gpiochip_add_data() so it shares the same
device-managed lifecycle, which also lets the manual gpiochip_remove()
error paths go away.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free in Mediatek pinctrl GPIO driver
Action: Apply Patch
AI Analysis

Impact

The Mediatek pinctrl driver allocates the gpio_chip structure with device‑managed memory yet registers it using the non‑managed function gpiochip_add_data(). When the driver is unloaded as a module, the device‑managed memory is freed while the GPIO chip remains registered, leading to a use‑after‑free condition that can cause a kernel crash or memory corruption.

Affected Systems

The flaw exists in any Linux kernel that bundles the Mediatek pinctrl driver for Mediatek SoCs. Because no kernel version range is specified, all kernels before the applied patch could be impacted.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, indicating a low exploitation probability. The attack vector requires the ability to unload or reload the affected module, a capability that is typically restricted to privileged users; this inference is made from the description that drivers can be built as modules and unbound. The primary risk is a kernel crash, and memory corruption could potentially lead to more severe outcomes if an attacker is able to exploit the use‑after‑free.

Generated by OpenCVE AI on September 19, 2026 at 12:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that registers the gpio_chip with devm_gpiochip_add_data(), ensuring the chip’s lifecycle matches device allocation.
  • Rebuild and deploy the updated Mediatek pinctrl module so the driver no longer uses the legacy registration path.
  • If a patch cannot be applied immediately, avoid unloading the medi prossed pinctrl driver or restrict module removal for that driver to prevent the use‑after‑free scenario.

Generated by OpenCVE AI on September 19, 2026 at 12:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated with device-managed memory but registered with the non-managed gpiochip_add_data(). This was harmless while the drivers were built-in, but once they can be built as modules and unbound/rmmod'd, devm frees the gpio_chip's memory while it is still registered, causing a use-after-free. Register it with devm_gpiochip_add_data() so it shares the same device-managed lifecycle, which also lets the manual gpiochip_remove() error paths go away.
Title pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:59.019Z

Reserved: 2026-09-16T12:21:13.870Z

Link: CVE-2026-92482

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:50.273

Modified: 2026-09-17T17:17:50.273

Link: CVE-2026-92482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T13:00:12Z

Weaknesses