Junglewise Threat Intelligence

CVE-2026-90121: Linux kernel GICv5 IRS use-after-free in per-CPU data teardown

CVE-2026-90121 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A resource cleanup bug in the Linux kernel's interrupt controller driver leaves stale pointers to freed memory in per-CPU data structures. On systems using ARM GICv5 interrupt routing, this could cause memory corruption or system instability during interrupt controller initialization failures or shutdown, potentially leading to denial of service or unpredictable system behavior.

Technical details

The vulnerability is a use-after-free flaw in the irqchip/gic-v5 driver's IRS (Interrupt Routing System) affinity setup code. During IRS initialization, the driver publishes an IRS pointer and IAFFID state in per-CPU data before completing the remaining initialization steps. If initialization fails in the error path, the IRS data is freed without clearing the published per-CPU pointers, leaving CPUs with dangling references to freed memory. The fix adds a gicv5_irs_clear_affinity() function that removes stale IRS pointers and invalidates IAFFID state during both initialization failure and normal teardown. This is a kernel-level bug requiring local or physical access to trigger, affecting ARM systems with GICv5 interrupt controllers.

Affected products

  • Linux Linux kernel affected versions with GICv5 IRS support (from commit 5cb1b6dab2de onward)

Timeline

  • 2026-09-17: disclosed

References

Related threats