Junglewise Threat Intelligence

CVE-2026-89455: Linux kernel PCI PLDA controller use-after-free in IRQ teardown

CVE-2026-89455 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's PCI PLDA host controller driver contains a memory safety bug in its interrupt cleanup code. During device removal, the driver frees interrupt domain data before deferred cleanup routines attempt to access it, potentially causing a kernel crash. This is a low-severity local issue affecting systems using the PLDA PCI controller.

Technical details

The vulnerability is a use-after-free in the plda_pcie_irq_domain_deinit() function affecting the PLDA PCI host controller driver (drivers/pci/controller/plda/pcie-plda-host.c). The root cause is a timing mismatch: per-event IRQs are requested with devm_request_irq() but the domain they are mapped into is removed via irq_domain_remove() before deferred cleanup runs. The devres framework defers the actual free_irq() call until after the driver's remove() function returns, allowing the domain to be freed while IRQs are still mapped into it. When devres later processes deferred cleanup, it dereferences the already-freed domain, causing a potential crash. The fix explicitly frees event IRQs with devm_free_irq() before removing domains, disposes IRQ mappings with irq_dispose_mapping(), and guards chained handler calls. Local kernel code execution is required to trigger this during device removal.

Affected products

  • Linux Linux kernel Versions with commit 76c911396807 (PCI: plda: Add host init/deinit and map bus functions) and later

Timeline

  • 2026-09-11: disclosed: Publicly disclosed via NVD
  • 2026-07-23: patched: Fix committed by Ali Tariq
  • 2026-09-07: other: Backported to stable kernel trees

References

Related threats