Executive brief
The Linux kernel's interrupt request mapping (regmap-irq) component has a memory allocation bug that can cause system crashes due to out-of-bounds memory access. This affects devices using certain interrupt controller configurations and can lead to kernel crashes during device initialization, disrupting system operation and potentially creating security-relevant memory corruption scenarios.
Technical details
The vulnerability is a heap out-of-bounds write in the regmap_add_irq_chip_fwnode() function. The root cause is an incorrect loop termination condition when allocating a 2D array for IRQ type registers: the code allocates memory num_config_regs times instead of num_config_bases times, leading to extra heap writes when num_config_regs exceeds num_config_bases. The bug is triggered during early kernel initialization when IRQ chip drivers call regmap_add_irq_chip_fwnode() with mismatched configuration parameters. KASAN reports indicate memory corruption in the kernel memory allocator. This is a kernel-level bug requiring a patched kernel; the fix updates the loop condition to iterate num_config_bases times instead of num_config_regs times.
Affected products
- Linux Linux Kernel Affected versions not specified in advisory; reportedly impacts devices such as db845c
Timeline
- 2025-12-08: disclosed