Junglewise Threat Intelligence

CVE-2026-72153: Linux kernel irqchip/crossbar incorrect index in domain free

CVE-2026-72153 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's interrupt controller chip (irqchip) crossbar driver used an incorrect index when freeing interrupt resources, causing interrupt mappings and hardware registers to remain improperly configured. This could result in system instability or resource leaks as interrupt connections remain active when they should be freed.

Technical details

The vulnerability exists in the crossbar_domain_free() function in drivers/irqchip/irq-crossbar.c. The function was using the irq_data->hwirq member directly as an index after resetting the domain data (which nullifies the pointer), and this member contains the source interrupt number rather than the GIC SPI number needed for proper indexing. This caused the function to access and reset the wrong irq_map[] entries and write incorrect values to hardware registers. Additionally, using the source interrupt number as an index could result in out-of-bounds access since it may exceed the valid index space. The fix uses the parent domain's irq_data->hwirq (adjusted by GIC_IRQ_START) as the correct index, ensuring proper resource cleanup and hardware register configuration.

Affected products

  • Linux Linux kernel Multiple versions (fix applied across stable branches from 3.x through 7.x)

Timeline

  • 2026-08-15: disclosed
  • 2026-06-21: patched: Commit 043db005a8d6932dc7d217c86307e9af0bc10ddc by Thomas Gleixner

References

Related threats