Executive brief
A vulnerability in the Linux kernel's ImgTec PDC interrupt chip driver could lead to a system crash. When the driver is removed, it fails to properly clean up certain internal resources, which can later be accessed by the system's power management or shutdown processes. This results in a 'use-after-free' condition that destabilizes the operating system.
Technical details
A vulnerability exists in the Linux kernel's irqchip/imgpdc driver (drivers/irqchip/irq-imgpdc.c) where generic chips and chained handlers are not properly decommissioned during driver removal. The generic chips remain on the global 'gc_list', allowing generic interrupt chip callbacks (suspend, resume, or shutdown) to access freed memory. Additionally, dangling chained handlers for peripheral and syswake interrupts can lead to spurious interrupts accessing invalid memory addresses. This use-after-free condition can be triggered after the driver has been removed, resulting in a kernel panic. The fix involves setting the IRQ_DOMAIN_FLAG_DESTROY_GC flag and explicitly clearing chained handlers in the pdc_intc_remove() function.
Affected products
- Linux Linux b6ef9161e43ad58c3824bd76dc87716276f0cd70
Timeline
- 2026-07-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0405a65e4ebd9eac13a765f9f02ac05851ca5421
- https://git.kernel.org/stable/c/37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057
- https://git.kernel.org/stable/c/41826e5297e67cd96a0a46fde06a5069a8ce436a
- https://git.kernel.org/stable/c/44567537a2623dcd2b4018a7f043cf8069579e5d
- https://git.kernel.org/stable/c/8176773dfceae7978b01c20b233693e072053700
- https://git.kernel.org/stable/c/83d7ec14b0938ad8cae008058fd6f912f4a9a312
- https://git.kernel.org/stable/c/b3a3831b2eb884641906fc5e46207b205b6aea13