Junglewise Threat Intelligence

CVE-2026-53226: Linux Kernel Rockchip GPIO use-after-free in IRQ chip removal

CVE-2026-53226 · Severity: info · CVSS 5.5 · Published 2026-06-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Rockchip GPIO driver could allow a local user to cause a system crash. The issue occurs when the driver is removed or shut down, failing to properly clean up internal memory structures. This can lead to a 'use-after-free' condition where the system attempts to access memory that no longer exists, resulting in a kernel panic and loss of availability.

Technical details

A vulnerability exists in drivers/gpio/gpio-rockchip.c where the driver allocates domain generic chips during the probe phase but fails to free them during teardown. Because the IRQ domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC, the generic chips are not automatically cleaned up when the domain is removed. These chips remain on the global gc_list and can be accessed by system-wide suspend, resume, or shutdown callbacks after the GPIO bank has been removed. This results in a use-after-free condition that can trigger a kernel crash. The fix involves explicitly calling irq_domain_remove_generic_chips() before removing the IRQ domain.

Affected products

  • Linux Linux 5.15 to 6.18.36, 7.0.13

Timeline

  • 2026-06-25: disclosed: Initial publication of the CVE record
  • 2026-06-09: patched: Fix committed to the Linux kernel tree

References