Junglewise Threat Intelligence

CVE-2026-89454: Linux kernel PCI PLDA IRQ domain resource leak in error paths

CVE-2026-89454 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel PCI PLDA host controller driver fails to properly clean up interrupt domain resources when initialization errors occur. This resource leak could cause the system to exhaust available interrupt domains over repeated initialization attempts, potentially leading to system instability or denial of service in scenarios involving device hotplug or driver reload cycles.

Technical details

The vulnerability is a resource leak in the plda_init_interrupts() function in drivers/pci/controller/plda/pcie-plda-host.c. When platform_get_irq() or irq_create_mapping() fails during IRQ domain initialization, the previously allocated IRQ domains are not deinitialized. The fix adds proper error handling paths that call plda_pcie_irq_domain_deinit() to clean up allocated resources before returning error codes. This is a fix-only patch with no remote attack surface; local impact is limited to resource exhaustion under repeated probe/removal cycles.

Affected products

  • Linux Linux kernel

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched

References

Related threats