SB2026072129 - Use-after-free in Linux kernel irqchip driver
Published: July 21, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-63798)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in the irq-imgpdc driver when handling interrupts after driver removal. A local user can trigger spurious interrupts that access freed memory to cause a denial of service.
The issue involves dangling chained handlers for peripheral and syswake interrupts, and generic chips may remain reachable by interrupt chip suspend, resume, or shutdown callbacks after the driver has been removed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0405a65e4ebd9eac13a765f9f02ac05851ca5421
- https://git.kernel.org/stable/c/37738fdf2ab1e504d1c63ce5bc0aeb6452d8f057
- https://git.kernel.org/stable/c/41826e5297e67cd96a0a46fde06a5069a8ce436a
- https://git.kernel.org/stable/c/44567537a2623dcd2b4018a7f043cf8069579e5d
- https://git.kernel.org/stable/c/8176773dfceae7978b01c20b233693e072053700
- https://git.kernel.org/stable/c/83d7ec14b0938ad8cae008058fd6f912f4a9a312
- https://git.kernel.org/stable/c/b3a3831b2eb884641906fc5e46207b205b6aea13
- https://git.kernel.org/stable/c/c2c7733101bb8c0b29ac9ee41073eaf602821a59