Description
In the Linux kernel, the following vulnerability has been resolved:

irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()

When its_irq_gic_domain_alloc() fails, the following
its_vpe_irq_domain_free() fails to invoke its_vep_teardown() for the
corresponding interrupt, which leaks the resource.

Invoke its_vpe_teardown() in the error handling path to avoid the leak.

[ tglx: Massaged change log ]
Published: 2026-09-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Leak
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel’s interrupt controller (GIC v3 ITS) causes a resource leak when the interrupt domain allocation function fails. The cleanup routine does not release the interrupt resources that were reserved earlier, leaving them dangling. This deficiency can lead to gradual exhaustion of kernel resources. The weakness matches CWE-772. The description confirms that the kernel developers have introduced a fix that invokes the proper teardown on error paths.

Affected Systems

All Linux kernel installations that use the GIC v3 ITS module and have not applied the recent patches will be affected. The vendor list indicates the Linux kernel itself; specific affected release numbers are not enumerated in the advisory, so any kernel revision before the fix could potentially be vulnerable.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity while the EPSS score of <1% suggests a very low exploitation probability in the current landscape. The vulnerability is not listed in CISA’s KEV catalog, implying there are no publicly documented exploits. An attacker would need to execute code with kernel-level privileges or induce repeated allocation failures locally, which is not directly documented in the description but is inferred from the nature of the resource leak. Based on the description, it is inferred that repeated allocation failures could cause resource exhaustion, potentially leading to a denial-of-service scenario. The flaw does not provide arbitrary code execution, so the risk level is moderate but still warrants an update to the fixed kernel to avoid potential denial-of-service.

Generated by OpenCVE AI on September 24, 2026 at 02:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that includes the GIC v3 ITS resource‑leak fix.
  • If a kernel upgrade is not immediately possible, apply the upstream patch retrieved from the Linux kernel git repository to manually install the fix for the ITS module.
  • Audit kernel logs and monitor system resource usage to detect any abnormal exhaustion of interrupt resources, and disable GIC v3 ITS if the feature is not required for your platform.

Generated by OpenCVE AI on September 24, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 24 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Low


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc() When its_irq_gic_domain_alloc() fails, the following its_vpe_irq_domain_free() fails to invoke its_vep_teardown() for the corresponding interrupt, which leaks the resource. Invoke its_vpe_teardown() in the error handling path to avoid the leak. [ tglx: Massaged change log ]
Title irqchip/gic-v3-its: Prevent leak in its_vpe_irq_domain_alloc()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:30.135Z

Reserved: 2026-09-16T12:21:13.874Z

Link: CVE-2026-92524

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:55.403

Modified: 2026-09-17T17:17:55.403

Link: CVE-2026-92524

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-92524 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T02:30:13Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime