-
CVE-2026-92482
- EPSS 0.19%
- Veröffentlicht 17.09.2026 16:09:59
- Zuletzt bearbeitet 17.09.2026 17:17:50
- Erkennungen
pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip The gpio_chip is allocated with device-managed memory but registered with the non-managed gpiochip_add_data(). This was harmless while the drivers were built-in, but once they can be built as modules and unbound/rmmod'd, devm frees the gpio_chip's memory while it is still registered, causing a use-after-free. Register it with devm_gpiochip_add_data() so it shares the same device-managed lifecycle, which also lets the manual gpiochip_remove() error paths go away.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
a6df410d420aa4ff316797d352f69e7ebae5ff98
Version <
b8fa1098ee9f627d38bdf7c0ef6c1a6058a4165b
Status
affected
Version
a6df410d420aa4ff316797d352f69e7ebae5ff98
Version <
9c650317ba553d297f3fc5f0ae40ec53d86f9dab
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
4.1
Status
affected
Version
0
Version <
4.1
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.088 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/b8fa1098ee9f627d38bdf7c0ef6c1a6058a4165b
https://git.kernel.org/stable/c/9c650317ba553d297f3fc5f0ae40ec53d86f9dab