-

CVE-2026-89455

PCI: plda: Fix use-after-free of event IRQs during teardown

In the Linux kernel, the following vulnerability has been resolved:

PCI: plda: Fix use-after-free of event IRQs during teardown

plda_pcie_irq_domain_deinit() removes pcie->event_domain via
irq_domain_remove(), but the per-event IRQs mapped from that domain
are requested with devm_request_irq() in plda_init_interrupts(). The
actual free_irq() for a devm-managed IRQ is deferred by devres until
after the calling probe()/remove() function returns.

This means irq_domain_remove() can free the domain's internal data
before the deferred free_irq() for IRQs still mapped into it has run.
When devres later processes that deferred cleanup, it can end up
dereferencing the already-freed domain.

Free each event IRQ explicitly with devm_free_irq() before removing
the domain. This triggers the free immediately and removes the IRQ
from the devres tracking list, so devres will not attempt to free it
a second time later.

Also dispose of the event, INTx, and MSI IRQ mappings with
irq_dispose_mapping() before their owning domains are removed.

Finally, guard the calls to irq_set_chained_handler_and_data() for
pcie->irq, pcie->msi_irq, and pcie->intx_irq so they only run when
those fields hold a valid (>0) IRQ number.

This is a pre-existing issue, flagged by automated review during work
on an earlier, unrelated patch to this driver.

Build-tested and boot-tested on StarFive VisionFive v1.2A board
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 76c9113968079140cb2f885631db422170f32105
Version < 1d0159e139261996a3ca21798d9114aab2124d3c
Status affected
Version 76c9113968079140cb2f885631db422170f32105
Version < 01c2f0c66bd1f892db9c6e82976da6b463cc4427
Status affected
Version 76c9113968079140cb2f885631db422170f32105
Version < e3589ca5f2e6477774753a2202c21509428d4701
Status affected
Version 76c9113968079140cb2f885631db422170f32105
Version < 26b73bae01d6eb81a4a38f36101812f20b2639de
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.11
Status affected
Version 0
Version < 6.11
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/1d0159e139261996a3ca21798d9114aab2124d3c
https://git.kernel.org/stable/c/01c2f0c66bd1f892db9c6e82976da6b463cc4427
https://git.kernel.org/stable/c/e3589ca5f2e6477774753a2202c21509428d4701
https://git.kernel.org/stable/c/26b73bae01d6eb81a4a38f36101812f20b2639de