Executive brief
The Linux kernel's interrupt controller driver (GIC-v3-ITS) fails to properly clean up resources when allocating interrupt domains for Virtual Processor Elements (VPEs). When initialization fails, kernel memory and hardware resources are not freed, leading to gradual resource exhaustion on systems using this interrupt controller.
Technical details
The vulnerability is a resource leak in the its_vpe_irq_domain_alloc() function within the ARM GIC-v3 ITS interrupt controller driver. When its_irq_gic_domain_alloc() fails during VPE interrupt domain allocation, the error handling path calls its_vpe_irq_domain_free() but does not invoke its_vpe_teardown() for the allocated VPE, leaving VPE resources allocated. The fix adds an explicit its_vpe_teardown() call in the error path and protects its_vpe_teardown() against double-free by checking if vpt_page is NULL before attempting cleanup. The vulnerability is local to systems running affected kernel versions and only manifests when initialization failures occur.
Affected products
- Linux Linux kernel 4.0 through 7.2 (specific patch dates indicate linux-4.x and linux-5.x through linux-7.x branches affected)
Timeline
- 2026-09-17: disclosed
- 2026-09-14: patched: Fix committed upstream and backported to stable kernels