Executive brief
A memory leak vulnerability was identified in the Linux kernel's MediaTek PCIe driver. When the system fails to find a specific interrupt request (IRQ) during setup, it fails to release previously allocated memory domains. While this primarily affects system stability and resource management on specific MediaTek hardware, it could theoretically be used to exhaust system memory over time if the error condition is repeatedly triggered.
Technical details
A resource leak exists in the mtk_pcie_setup_irq() function within drivers/pci/controller/pcie-mediatek-gen3.c. The vulnerability is caused by an incorrect initialization sequence where IRQ domains are allocated before the controller's IRQ is successfully fetched. If platform_get_irq() fails, the function returns an error immediately without freeing the allocated IRQ domains. An attacker with the ability to trigger repeated PCIe initialization failures could potentially cause kernel memory exhaustion. The fix involves reordering the operations to ensure the IRQ is found before memory allocation occurs.
Affected products
- Linux Linux Kernel 5.13 to 7.0.10
Timeline
- 2026-03-24: disclosed: Initial patch submitted by Chen-Yu Tsai
- 2026-07-19: advisory: CVE-2026-63862 published by NVD
References
- https://git.kernel.org/stable/c/07a5ecb94768cbf76fe659e9924000e9ced0c8a6
- https://git.kernel.org/stable/c/0a2d60edc3e57c9512e239ebdfd12204d3368560
- https://git.kernel.org/stable/c/215d4273347b9010a9deae378b0df79c163f707d
- https://git.kernel.org/stable/c/5573c44cb3fd01a9f62d569ae9ac870ef5f0e0ba
- https://git.kernel.org/stable/c/946b31b5a699a2760ee52af0055e5ebf29c5f4cb
- https://git.kernel.org/stable/c/abd3c1927d33766aef39c4640880e3d2637429c2